Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,066cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,692 exploits
Referência
CVE-2023-34362
CVE-2023-34362CRITICALunder attackransomware
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
Referência
CVE-2023-34362
CVE-2023-34362CRITICALunder attackransomware
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
Referência
CVE-2026-65710
sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption
41RISK
open
Referência
CVE-2021-1497
CVE-2021-1497CRITICALunder attack
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open
Referência
CVE-2022-29303
CVE-2022-29303CRITICALunder attack
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RISK
open
Referência
CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Referência
CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Referência
CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Referência
CVE-2018-0296
CVE-2018-0296HIGHunder attack
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
Referência
CVE-2018-0296
CVE-2018-0296HIGHunder attack
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISK
open
Referência
CVE-2021-22986
CVE-2021-22986CRITICALunder attackransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
Referência
CVE-2021-22986
CVE-2021-22986CRITICALunder attackransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISK
open
Referência
CVE-2019-1653
CVE-2019-1653HIGHunder attack
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
Referência
CVE-2019-1653
CVE-2019-1653HIGHunder attack
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
Referência
CVE-2021-33044
CVE-2021-33044CRITICALunder attack
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
Referência
CVE-2021-36260
CVE-2021-36260CRITICALunder attack
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
Referência
CVE-2021-36260
CVE-2021-36260CRITICALunder attack
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
Referência
CVE-2020-13379
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows
60RISK
open
Referência
CVE-2023-0600
WP Visitor Statistics (Real Time Traffic) < 6.9 - Unauthenticated SQLi
63RISK
open
Referência
CVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
Referência
CVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
Referência
CVE-2017-7269
CVE-2017-7269CRITICALunder attack
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
Referência
CVE-2025-34103
WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
63RISK
open
Referência
CVE-2023-21839
CVE-2023-21839HIGHunder attack
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
Referência
CVE-2022-1040
CVE-2022-1040CRITICALunder attack
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
Referência
CVE-2020-7961
CVE-2020-7961CRITICALunder attack
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
Referência
CVE-2020-7961
CVE-2020-7961CRITICALunder attack
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
Referência
CVE-2021-31207
CVE-2021-31207MEDIUMunder attackransomware
Microsoft Exchange Server Security Feature Bypass Vulnerability
100RISK
open
Referência
CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Referência
CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
previouspage 289 / 724next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.