Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
SolarView Compact 6.00 - Directory Traversal
CVE-2022-29298remotehardware03 Jun 2022
SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.
50RISK
open
Exploit-DBVexDay Proof
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2)
CVE-2020-7246webappsphp25 May 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
Exploit-DB
m1k1o's Blog v.10 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-23626HIGHwebappsphp23 May 2022
Insufficient file checks in m1k1o/blog
41RISK
open
Exploit-DB
SolarView Compact 6.0 - OS Command Injection
CVE-2022-29303CRITICALunder attackremotehardware17 May 2022
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RISK
open
Exploit-DB
Survey Sparrow Enterprise Survey Software 2022 - Stored Cross-Site Scripting (XSS)
CVE-2022-29727webappsmultiple17 May 2022
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup param
23RISK
open
Exploit-DB
Showdoc 2.10.3 - Stored Cross-Site Scripting (XSS)
CVE-2022-0967MEDIUMwebappsphp17 May 2022
Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in star7th/showdoc
33RISK
open
Exploit-DB
SDT-CW3B1 1.1.0 - OS Command Injection
CVE-2021-46422remotehardware17 May 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
Exploit-DB
Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)
CVE-2022-28080webappsphp12 May 2022
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
50RISK
open
Exploit-DB
College Management System 1.0 - 'course_code' SQL Injection (Authenticated)
CVE-2022-28079webappsphp12 May 2022
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
43RISK
open
Exploit-DB
F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
CVE-2022-1388CRITICALunder attackransomwareremotemultiple12 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Exploit-DB
TLR-2005KSH - Arbitrary File Delete
CVE-2021-46424webappshardware12 May 2022
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de
50RISK
open
Exploit-DB
Apache CouchDB 3.2.1 - Remote Code Execution (RCE)
CVE-2022-24706CRITICALunder attackremotelinux11 May 2022
Remote Code Execution Vulnerability in Packaging
100RISK
open
Exploit-DB
WebTareas 2.4 - Blind SQLi (Authenticated)
CVE-2021-43481webappsphp11 May 2022
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RISK
open
Exploit-DB
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
CVE-2022-28213remotemultiple11 May 2022
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n
28RISK
open
Exploit-DB
PHProjekt PhpSimplyGest v1.3. - Stored Cross-Site Scripting (XSS)
CVE-2022-27308webappsphp11 May 2022
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RISK
open
Exploit-DB
Bookeen Notea - Directory Traversal
CVE-2021-45783remoteandroid11 May 2022
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to
23RISK
open
Exploit-DB
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
CVE-2021-31673webappsmultiple11 May 2022
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RISK
open
Exploit-DB
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
CVE-2022-29457remotewindows11 May 2022
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131
23RISK
open
Exploit-DB
ExifTool 12.23 - Arbitrary Code Execution
CVE-2021-22204MEDIUMunder attacklocallinux11 May 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Exploit-DB
Wondershare Dr.Fone 12.0.7 - Remote Code Execution (RCE)
CVE-2021-44596remotewindows11 May 2022
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an
28RISK
open
Exploit-DB
Google Chrome 78.0.3904.70 - Remote Code Execution
CVE-2019-13720HIGHunder attackremotemultiple11 May 2022
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
83RISK
open
Exploit-DB
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
CVE-2022-1103webappsphp11 May 2022
Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
28RISK
open
Exploit-DB
MyBB 1.8.29 - MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-24734HIGHwebappsphp11 May 2022
Remote code execution in mybb
78RISK
open
Exploit-DB
Ruijie Reyee Mesh Router - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43164remotehardware11 May 2022
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
35RISK
open
Exploit-DBVexDay Proof
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
CVE-2021-44595localwindows11 May 2022
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RISK
open
Exploit-DB
Akka HTTP 10.1.14 - Denial of Service
CVE-2021-42697remotemultiple11 May 2022
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RISK
open
Exploit-DB
Navigate CMS 2.9.4 - Server-Side Request Forgery (SSRF) (Authenticated)
CVE-2022-28117webappsphp11 May 2022
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RISK
open
Exploit-DB
DLINK DIR850 - Insecure Access Control
CVE-2021-46378remotehardware11 May 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote
35RISK
open
Exploit-DB
DLINK DIR850 - Open Redirect
CVE-2021-46379remotehardware11 May 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RISK
open
Exploit-DB
TLR-2005KSH - Arbitrary File Upload
CVE-2021-45428webappshardware11 May 2022
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.