Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,695 exploits
Exploit-DBVexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142webappsphp25 Mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISK
open
Exploit-DBVexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
CVE-2022-26149webappsphp25 Mar 2023
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISK
open
Exploit-DBVexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
CVE-2022-35155MEDIUMwebappsphp25 Mar 2023
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISK
open
Exploit-DBVexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521webappsphp25 Mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISK
open
Exploit-DBVexDay Proof
Wordpress Plugin Zephyr Project Manager 3.2.42 - Multiple SQLi
CVE-2022-2840webappsphp06 Oct 2022
Zephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi
28RISK
open
Exploit-DBVexDay Proof
Wordpress Plugin WP-UserOnline 2.88.0 - Stored Cross Site Scripting (XSS)
CVE-2022-2941MEDIUMwebappsphp23 Sep 2022
WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
33RISK
open
Exploit-DBVexDay Proof
Bookwyrm v0.4.3 - Authentication Bypass
CVE-2022-2651CRITICALwebappsmultiple20 Sep 2022
Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
53RISK
open
Exploit-DBVexDay Proof
Gitea 1.16.6 - Remote Code Execution (RCE) (Metasploit)
CVE-2022-30781webappsmultiple15 Sep 2022
Gitea before 1.16.7 does not escape git fetch remote.
60RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Duplicator 1.4.7 - Information Disclosure
CVE-2022-2552webappsphp01 Aug 2022
Duplicator < 1.4.7.1 - Unauthenticated System Information Disclosure
43RISK
open
Exploit-DBVexDay Proof
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2)
CVE-2020-7246webappsphp25 May 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
Exploit-DBVexDay Proof
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
CVE-2021-44595localwindows11 May 2022
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RISK
open
Exploit-DBVexDay Proof
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
CVE-2021-42840webappsphp17 Nov 2021
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-41773HIGHunder attackransomwarewebappsmultiple11 Nov 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
CVE-2021-42013CRITICALunder attackransomwarewebappsmultiple11 Nov 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Exploit-DBVexDay Proof
Movable Type 7 r.5002 - XMLRPC API OS Command Injection (Metasploit)
CVE-2021-20837webappscgi29 Oct 2021
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - Remote Code Execution (RCE)
CVE-2018-12613webappsphp25 Oct 2021
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)
CVE-2021-42013CRITICALunder attackransomwarewebappsmultiple13 Oct 2021
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
Exploit-DBVexDay Proof
Google SLO-Generator 2.0.0 - Code Execution
CVE-2021-22557MEDIUMlocallinux07 Oct 2021
Code execution in SLO Generator via YAML Payload
33RISK
open
Exploit-DBVexDay Proof
Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)
CVE-2021-41773HIGHunder attackransomwarewebappsmultiple06 Oct 2021
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DBVexDay Proof
qdPM 9.1 - Remote Code Execution (Authenticated)
CVE-2020-7246webappsphp04 Aug 2021
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation
CVE-2021-22555HIGHunder attacklocallinux15 Jul 2021
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
Exploit-DBVexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated) (2)
CVE-2021-22911webappslinux07 Jul 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
Exploit-DBVexDay Proof
Websvn 2.6.0 - Remote Code Execution (Unauthenticated)
CVE-2021-32305webappsphp21 Jun 2021
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search paramet
60RISK
open
Exploit-DBVexDay Proof
Polkit 0.105-26 0.117-2 - Local Privilege Escalation
CVE-2021-3560HIGHunder attacklocallinux15 Jun 2021
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
Exploit-DBVexDay Proof
Rocket.Chat 3.12.1 - NoSQL Injection (Unauthenticated)
CVE-2021-22911webappslinux07 Jun 2021
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
Exploit-DBVexDay Proof
PHPFusion 9.03.50 - Remote Code Execution
CVE-2020-24949webappsphp28 May 2021
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a cr
50RISK
open
Exploit-DBVexDay Proof
ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
CVE-2015-3306remotelinux26 May 2021
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
Exploit-DBVexDay Proof
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
CVE-2020-29607webappsphp26 May 2021
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISK
open
Exploit-DBVexDay Proof
Chamilo LMS 1.11.14 - Remote Code Execution (Authenticated)
CVE-2021-31933HIGHwebappsphp14 May 2021
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete
46RISK
open
Exploit-DBVexDay Proof
GravCMS 1.10.7 - Unauthenticated Arbitrary File Write (Metasploit)
CVE-2021-21425CRITICALwebappsphp21 Apr 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.