Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
DLINK DIR850 - Insecure Access Control
CVE-2021-46378remotehardware11 May 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote
35RISK
open
Exploit-DB
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
CVE-2022-1103webappsphp11 May 2022
Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
28RISK
open
Exploit-DB
Akka HTTP 10.1.14 - Denial of Service
CVE-2021-42697remotemultiple11 May 2022
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RISK
open
Exploit-DB
Anuko Time Tracker - SQLi (Authenticated)
CVE-2022-24707HIGHwebappsphp11 May 2022
SQL injection in anuko timetracker
41RISK
open
Exploit-DB
Gitlab 14.9 - Authentication Bypass
CVE-2022-1162CRITICALwebappsruby26 Apr 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RISK
open
Exploit-DB
GitLab 14.9 - Stored Cross-Site Scripting (XSS)
CVE-2022-1175HIGHwebappsruby26 Apr 2022
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RISK
open
Exploit-DB
Easy Appointments 1.4.2 - Information Disclosure
CVE-2022-0482CRITICALwebappsphp19 Apr 2022
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISK
open
Exploit-DB
Zyxel NWA-1100-NH - Command Injection
CVE-2021-4039CRITICALremotehardware19 Apr 2022
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to exec
70RISK
open
Exploit-DB
WordPress Plugin Popup Maker 1.16.5 - Stored Cross-Site Scripting (Authenticated)
CVE-2022-1104webappsphp19 Apr 2022
Popup Maker < 1.16.5 - Admin+ Stored Cross-Site Scripting
35RISK
open
Exploit-DB
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
CVE-2022-24181webappsphp19 Apr 2022
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to
38RISK
open
Exploit-DB
REDCap 11.3.9 - Stored Cross Site Scripting
CVE-2021-42136webappsphp19 Apr 2022
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows
23RISK
open
Exploit-DB
Telesquare TLR-2855KS6 - Arbitrary File Creation
CVE-2021-46418webappshardware11 Apr 2022
An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
43RISK
open
Exploit-DB
SAM SUNNY TRIPOWER 5.0 - Insecure Direct Object Reference (IDOR)
CVE-2021-46416MEDIUMwebappshardware11 Apr 2022
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups acce
33RISK
open
Exploit-DB
Telesquare TLR-2855KS6 - Arbitrary File Deletion
CVE-2021-46419webappshardware11 Apr 2022
An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil
60RISK
open
Exploit-DB
Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI)
CVE-2021-46417remotelinux11 Apr 2022
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISK
open
Exploit-DB
Sherpa Connector Service v2020.2.20328.2050 - Unquoted Service Path
CVE-2022-23909localwindows07 Apr 2022
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
23RISK
open
Exploit-DB
Kramer VIAware - Remote Code Execution (RCE) (Root)
CVE-2021-36356remotehardware07 Apr 2022
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa
50RISK
open
Exploit-DB
binutils 2.37 - Objdump Segmentation Fault
CVE-2021-43149locallinux07 Apr 2022
20RISK
open
Exploit-DB
Kramer VIAware - Remote Code Execution (RCE) (Root)
CVE-2021-35064remotehardware07 Apr 2022
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn
60RISK
open
Exploit-DB
Kramer VIAware 2.5.0719.1034 - Remote Code Execution (RCE)
CVE-2019-17124remotehardware30 Mar 2022
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
28RISK
open
Exploit-DB
ImpressCMS 1.4.2 - Remote Code Execution (RCE)
CVE-2021-26599webappsphp30 Mar 2022
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
43RISK
open
Exploit-DB
WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS
CVE-2021-24405webappsphp30 Mar 2022
Easy Cookie Policy <= 1.6.2 - Broken Access Control to Stored Cross-Site Scripting
28RISK
open
Exploit-DB
Ivanti Endpoint Manager 4.6 - Remote Code Execution (RCE)
CVE-2021-44529CRITICALunder attackransomwareremotemultiple22 Mar 2022
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RISK
open
Exploit-DB
iRZ Mobile Router - CSRF to RCE
CVE-2022-27226remotehardware22 Mar 2022
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in
35RISK
open
Exploit-DB
Apache APISIX 2.12.1 - Remote Code Execution (RCE)
CVE-2022-24112CRITICALunder attackremotemultiple16 Mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open
Exploit-DB
Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
CVE-2021-45010webappsphp16 Mar 2022
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RISK
open
Exploit-DB
Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
CVE-2021-40964webappsphp16 Mar 2022
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RISK
open
Exploit-DB
Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-26965webappsphp16 Mar 2022
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RISK
open
Exploit-DB
Webmin 1.984 - Remote Code Execution (Authenticated)
CVE-2022-0824HIGHwebappslinux09 Mar 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISK
open
Exploit-DB
Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)
CVE-2022-0847HIGHunder attacklocallinux08 Mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.