Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
CVE-2022-22947CRITICALunder attackwebappsjava07 Mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
Exploit-DB
part-db 0.5.11 - Remote Code Execution (RCE)
CVE-2022-0848CRITICALwebappsphp07 Mar 2022
OS Command Injection in part-db/part-db
60RISK
open
Exploit-DB
Xerte 3.10.3 - Directory Traversal (Authenticated)
CVE-2021-44665webappsphp02 Mar 2022
A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via
23RISK
open
Exploit-DB
Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-44664webappsphp02 Mar 2022
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupl
28RISK
open
Exploit-DB
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
CVE-2021-46387webappsmultiple02 Mar 2022
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RISK
open
Exploit-DB
Casdoor 1.13.0 - SQL Injection (Unauthenticated)
CVE-2022-24124webappsmultiple28 Feb 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RISK
open
Exploit-DB
ICL ScadaFlex II SCADA Controllers SC-1/SC-2 1.03.07 - Remote File CRUD
CVE-2022-25359remotehardware23 Feb 2022
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, dele
35RISK
open
Exploit-DB
WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
CVE-2021-24762webappsphp21 Feb 2022
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISK
open
Exploit-DB
Thinfinity VirtualUI 2.5.41.0 - IFRAME Injection
CVE-2021-45092webappsmultiple21 Feb 2022
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RISK
open
Exploit-DB
Thinfinity VirtualUI 2.5.26.2 - Information Disclosure
CVE-2021-46354webappsmultiple21 Feb 2022
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vuln
28RISK
open
Exploit-DB
WordPress Plugin WP User Frontend 3.5.25 - SQLi (Authenticated)
CVE-2021-25076webappsphp21 Feb 2022
WP User Frontend < 3.5.26 - SQL Injection to Reflected Cross-Site Scripting
28RISK
open
Exploit-DB
FileCloud 21.2 - Cross-Site Request Forgery (CSRF)
CVE-2022-25241webappsphp21 Feb 2022
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
23RISK
open
Exploit-DB
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
CVE-2021-43062MEDIUMwebappsmultiple18 Feb 2022
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0
53RISK
open
Exploit-DB
Hotel Druid 3.0.3 - Remote Code Execution (RCE)
CVE-2022-22909webappsphp18 Feb 2022
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
35RISK
open
Exploit-DB
WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
CVE-2022-0441webappsphp18 Feb 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open
Exploit-DB
ServiceNow - Username Enumeration
CVE-2021-45901webappsmultiple16 Feb 2022
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending
28RISK
open
Exploit-DB
WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
CVE-2021-24966webappsphp16 Feb 2022
Error Log Viewer Plugin <= 1.1.1 - Admin+ Arbitrary File Clearing
23RISK
open
Exploit-DB
Hospital Management Startup 1.0 - 'Multiple' SQLi
CVE-2022-23366webappsphp10 Feb 2022
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
23RISK
open
Exploit-DB
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
CVE-2021-24931webappsphp10 Feb 2022
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RISK
open
Exploit-DB
AtomCMS v2.0 - SQLi
CVE-2022-24223webappsphp09 Feb 2022
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
50RISK
open
Exploit-DB
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
CVE-2020-35749webappsphp08 Feb 2022
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RISK
open
Exploit-DB
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
CVE-2019-18818webappsnodejs08 Feb 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
Exploit-DB
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
CVE-2021-46398webappsmultiple08 Feb 2022
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RISK
open
Exploit-DB
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
CVE-2021-24901webappsphp08 Feb 2022
Security Audit <= 1.0.0 - Admin+ Stored Cross Site Scripting
23RISK
open
Exploit-DB
Hospital Management System 4.0 - 'multiple' SQL Injection
CVE-2022-24263webappsphp08 Feb 2022
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
23RISK
open
Exploit-DB
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
CVE-2022-0448webappsphp08 Feb 2022
CP Blocks < 1.0.15 - Admin+ Stored Cross-Site Scripting
23RISK
open
Exploit-DB
Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit)
CVE-2022-22832webappsmultiple04 Feb 2022
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RISK
open
Exploit-DB
Servisnet Tessa - Privilege Escalation (Metasploit)
CVE-2022-22833webappsmultiple04 Feb 2022
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.
28RISK
open
Exploit-DB
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
CVE-2021-24247webappsphp02 Feb 2022
Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
23RISK
open
Exploit-DB
Moodle 3.11.4 - SQL Injection
CVE-2022-0332webappsphp02 Feb 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.