Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC3
cbk914/CVE-2022-26134_check
CVE-2022-26134CRITICALunder attackransomware15 Jan 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
nhamle2/CVE-2015-8660
CVE-2015-866015 Jan 2023
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISK
open
GitHub PoC4
iliass-dahman/CVE-2022-22963-POC
CVE-2022-22963CRITICALunder attack15 Jan 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC2
cbk914/CVE-2022-30525_check
CVE-2022-30525CRITICALunder attack15 Jan 2023
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC2
Cacti: Unauthenticated Remote Code Execution Exploit in Ruby
CVE-2022-46169CRITICALunder attack15 Jan 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC9
Exploit to CVE-2022-46169 vulnerability
CVE-2022-46169CRITICALunder attack13 Jan 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC1
CVE 2022-45299
CVE-2022-45299CRITICAL13 Jan 2023
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
48RISK
open
GitHub PoC6
Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.
CVE-2022-21661HIGH13 Jan 2023
SQL injection in WordPress
78RISK
open
GitHub PoC2
cve-2010-1622 Learning Environment
CVE-2010-162211 Jan 2023
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISK
open
GitHub PoC
CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8
CVE-2021-29447HIGH10 Jan 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC326
Wh04m1001/CVE-2023-21752
CVE-2023-21752HIGH10 Jan 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
CVE-2017-16995 Linux POC
CVE-2017-1699509 Jan 2023
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC28
CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad
CVE-2023-0297CRITICAL09 Jan 2023
Code Injection in pyload/pyload
85RISK
open
GitHub PoC
G01d3nW01f/CVE-2021-43798
CVE-2021-43798HIGHunder attack09 Jan 2023
Grafana path traversal
100RISK
open
GitHub PoC1
.NET console application that exploits CVE-2018-9995 vulnerability
CVE-2018-999509 Jan 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC
zabbix saml bypass
CVE-2022-23131CRITICALunder attack09 Jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC
CVE-2017-7308 POC
CVE-2017-730809 Jan 2023
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISK
open
GitHub PoC
Sophos EXploit
CVE-2022-1040CRITICALunder attack08 Jan 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC11
Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.
CVE-2022-39073CRITICAL07 Jan 2023
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an att
48RISK
open
GitHub PoC26
Dell Driver EoP (CVE-2021-21551)
CVE-2021-21551HIGHunder attack07 Jan 2023
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
GitHub PoC2
CVE-2018-19321
CVE-2018-19321HIGHunder attackransomware07 Jan 2023
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RISK
open
GitHub PoC37
CVE-2021-38003 exploits extracted from https://twitter.com/WhichbufferArda/status/1609604183535284224
CVE-2021-38003HIGHunder attack07 Jan 2023
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
83RISK
open
GitHub PoC1
wr0x00/cve-2022-23131
CVE-2022-23131CRITICALunder attack07 Jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC
POC Exploit for CVE-2022-44149
CVE-2022-44149HIGH06 Jan 2023
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
53RISK
open
GitHub PoC10
CVE-2022-44877 Centos Web Panel 7 Unauthenticated Remote Code Execution
CVE-2022-44877CRITICALunder attack06 Jan 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
GitHub PoC103
numanturle/CVE-2022-44877
CVE-2022-44877CRITICALunder attack05 Jan 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
GitHub PoC5
Proof of concept for exploiting the Heartbeat Extension bug detailed in the CVE-2014-0160. :old_key: :unlock:
CVE-2014-0160HIGHunder attack05 Jan 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC29
PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22
CVE-2022-46169CRITICALunder attack05 Jan 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
ajith737/Dirty-Pipe-CVE-2022-0847-POCs
CVE-2022-0847HIGHunder attack04 Jan 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC12
Basic POC exploit for CVE-2022-46164
CVE-2022-46164CRITICAL04 Jan 2023
Account takeover via prototype vulnerability
60RISK
open
previouspage 285 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.