Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
77,231 exploits
VulnCheck XDB
initial-access
CVE-2023-5016417 Dec 2023
Apache Struts: File upload component had a directory traversal vulnerability
45RISK
open
VulnCheck XDB
initial-access
CVE-2023-4907017 Dec 2023
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware16 Dec 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
dcm2406/CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware16 Dec 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC2
Simulates CVE-2023-4966 Citrix Bleed overread bug
CVE-2023-4966CRITICALunder attackransomware16 Dec 2023
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALunder attackransomware16 Dec 2023
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack15 Dec 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC13
A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass
CVE-2023-32315HIGHunder attack15 Dec 2023
Openfire administration console authentication bypass
100RISK
open
Metasploit600
MajorDoMo Command Injection
CVE-2023-5091715 Dec 2023
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE:
50RISK
open
GitHub PoC
ZhiQiAnSecFork/cve-2017-16995
CVE-2017-1699515 Dec 2023
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack15 Dec 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALunder attack15 Dec 2023
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-5016415 Dec 2023
Apache Struts: File upload component had a directory traversal vulnerability
45RISK
open
GitHub PoC
ZhiQiAnSecFork/DirtyCOW_CVE-2016-5195
CVE-2016-5195HIGHunder attack15 Dec 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Remote Code Execution exploit for PrimeFaces 5.x - EL Injection (CVE-2017-1000486)
CVE-2017-1000486CRITICALunder attack15 Dec 2023
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
GitHub PoC
markyu0401/CVE-2021-3560-Polkit-Privilege-Escalation
CVE-2021-3560HIGHunder attack15 Dec 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC5
Exihibitor Web Ui 1.7.1 RCE, CVE-2019-5029
CVE-2019-5029CRITICAL14 Dec 2023
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7
60RISK
open
GitHub PoC2
SQL Injection in 3CX CRM Integration
CVE-2023-49954CRITICAL14 Dec 2023
The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search stri
48RISK
open
GitHub PoC1
imperva/CVE-2023-22524
CVE-2023-22524CRITICAL14 Dec 2023
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An att
53RISK
open
GitHub PoC25
Atlassian Companion RCE Vulnerability Proof of Concept
CVE-2023-22524CRITICAL14 Dec 2023
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An att
53RISK
open
GitHub PoC
CVE-2022-4047 poc
CVE-2022-4047CRITICAL14 Dec 2023
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-4907014 Dec 2023
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RISK
open
VulnCheck XDB
local
CVE-2023-2640HIGH13 Dec 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack13 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
local
CVE-2023-32629HIGH13 Dec 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISK
open
GitHub PoC86
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
CVE-2023-6553CRITICAL13 Dec 2023
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
GitHub PoC
mareks1007/cve-2017-16995
CVE-2017-1699513 Dec 2023
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
VulnCheck XDB
initial-access
CVE-2023-6553CRITICAL13 Dec 2023
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
GitHub PoC
CVE-2023-23752 Joomla Unauthenticated Information Disclosure
CVE-2023-23752MEDIUMunder attack13 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC9
CVE-2021-40438 Apache <= 2.4.48 SSRF exploit
CVE-2021-40438CRITICALunder attackransomware12 Dec 2023
mod_proxy SSRF
100RISK
open
previouspage 443 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.