Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
CVE-2021-24300webappsphp02 Feb 2022
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
43RISK
open
Exploit-DB
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2017-9841CRITICALunder attackwebappsphp02 Feb 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
Exploit-DB
Moodle 3.11.4 - SQL Injection
CVE-2022-0332webappsphp02 Feb 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RISK
open
Exploit-DB
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
CVE-2021-24488webappsphp02 Feb 2022
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
43RISK
open
Exploit-DB
Chamilo LMS 1.11.14 - Account Takeover
CVE-2021-37391webappsphp02 Feb 2022
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator
23RISK
open
Exploit-DB
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24926webappsphp02 Feb 2022
Domain Check < 1.0.17 - Reflected Cross-Site Scripting
43RISK
open
Exploit-DB
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
CVE-2021-24247webappsphp02 Feb 2022
Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
23RISK
open
Exploit-DB
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
CVE-2022-0377webappsphp02 Feb 2022
LearnPress < 4.1.5 - Arbitrary Image Renaming
23RISK
open
Exploit-DB
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
CVE-2021-24786HIGHwebappsphp02 Feb 2022
Download Monitor < 4.4.5 - Admin+ SQL Injection
61RISK
open
Exploit-DB
WordPress Plugin RegistrationMagic V 5.0.1.5 - SQL Injection (Authenticated)
CVE-2021-24862webappsphp27 Jan 2022
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RISK
open
Exploit-DB
PolicyKit-1 0.105-31 - Privilege Escalation
CVE-2021-4034HIGHunder attackransomwarelocallinux27 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
WordPress Plugin Mortgage Calculators WP 1.52 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24904webappsphp27 Jan 2022
Mortgage Calculators WP < 1.56 - Admin+ Stored Cross-Site Scripting
23RISK
open
Exploit-DB
WordPress Plugin Modern Events Calendar V 6.1 - SQL Injection (Unauthenticated)
CVE-2021-24946webappsphp27 Jan 2022
Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
60RISK
open
Exploit-DB
Oracle WebLogic Server 14.1.1.0.0 - Local File Inclusion
CVE-2022-21371HIGHremotewindows27 Jan 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
Exploit-DB
PHPIPAM 1.4.4 - SQLi (Authenticated)
CVE-2022-23046webappsphp25 Jan 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open
Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure
CVE-2022-23178webappshardware18 Jan 2022
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RISK
open
Exploit-DB
WordPress Plugin Frontend Uploader 1.3.2 - Stored Cross Site Scripting (XSS) (Unauthenticated)
CVE-2021-24563webappsphp12 Jan 2022
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RISK
open
Exploit-DB
Open-AudIT Community 4.2.0 - Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-44916webappsphp10 Jan 2022
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad
23RISK
open
Exploit-DB
CoreFTP Server build 725 - Directory Traversal (Authenticated)
CVE-2022-22836remotewindows10 Jan 2022
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP
23RISK
open
Exploit-DB
VUPlayer 2.49 - '.wax' Local Buffer Overflow (DEP Bypass)
CVE-2009-0182localwindows10 Jan 2022
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RISK
open
Exploit-DB
Gerapy 0.9.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43857CRITICALremotepython05 Jan 2022
Gerapy may contain remote code execution vulnerability
60RISK
open
Exploit-DB
Automox Agent 32 - Local Privilege Escalation
CVE-2021-43326localwindows05 Jan 2022
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
23RISK
open
Exploit-DB
WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read (Unauthenticated)
CVE-2021-39312HIGHwebappsphp05 Jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISK
open
Exploit-DB
WordPress Plugin WP Visitor Statistics 4.7 - SQL Injection
CVE-2021-24750webappsphp05 Jan 2022
WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
50RISK
open
Exploit-DB
SAFARI Montage 8.5 - Reflected Cross Site Scripting (XSS)
CVE-2021-45425webappsphp05 Jan 2022
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip
23RISK
open
Exploit-DB
ConnectWise Control 19.2.24707 - Username Enumeration
CVE-2019-16516remotemultiple05 Jan 2022
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer
28RISK
open
Exploit-DB
Nettmp NNT 5.1 - SQLi Authentication Bypass
CVE-2021-45814webappsphp05 Jan 2022
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RISK
open
Exploit-DB
WBCE CMS 1.5.1 - Admin Password Reset
CVE-2021-3817CRITICALwebappsphp20 Dec 2021
SQL Injection in wbce/wbce_cms
60RISK
open
Exploit-DB
Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
CVE-2021-44848webappsmultiple16 Dec 2021
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RISK
open
Exploit-DB
Apache Log4j2 2.14.1 - Information Disclosure
CVE-2021-44228CRITICALunder attackransomwareremotejava14 Dec 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.