Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,334cataloged exploits
35,501CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,142VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
77,302 exploits
Metasploit600
Netis router MW5360 unauthenticated RCE.
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter
65RISK
open ↗VulnCheck XDB
initial-access
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RISK
open ↗Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISK
open ↗Metasploit600
Ivanti Connect Secure Unauthenticated Remote Code Execution
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISK
open ↗VulnCheck XDB
initial-access
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RISK
open ↗Metasploit300
Wordpress POST SMTP Account Takeover
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISK
open ↗VulnCheck XDB
initial-access
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RISK
open ↗GitHub PoC★ 1
PoC for CVE-2022-1388 affecting F5 BIG-IP.
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
initial-access
Apache Struts: File upload component had a directory traversal vulnerability
45RISK
open ↗VulnCheck XDB
initial-access
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open ↗VulnCheck XDB
initial-access
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerabilit
35RISK
open ↗VulnCheck XDB
initial-access
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /w
60RISK
open ↗GitHub PoC★ 12
PoC Script for CVE-2022-36267: Exploits an unauthenticated remote command injection vulnerability in Airspan AirSpot 5410 antenna.
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerabilit
35RISK
open ↗VulnCheck XDB
infoleak
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RISK
open ↗VulnCheck XDB
initial-access
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RISK
open ↗GitHub PoC
MS-NRPC (Microsoft NetLogon Remote Protocol)/CVE-2020-1472
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗VulnCheck XDB
infoleak
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open ↗GitHub PoC
Local Privilege Escalation (LPE) vulnerability in Polkit - Pwnkit
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
initial-access
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the
78RISK
open ↗VulnCheck XDB
initial-access
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config
75RISK
open ↗GitHub PoC★ 1
touch 生成文件
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.