Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
77,231 exploits
GitHub PoC126
Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)
CVE-2023-46604CRITICALunder attackransomware03 Nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-536003 Nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware03 Nov 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
Wordpress CVE-2023-5360
CVE-2023-536003 Nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC10
Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.
CVE-2023-536002 Nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
NestyF/SSH_Enum_CVE-2018-15473
CVE-2018-15473MEDIUM02 Nov 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
VulnCheck XDB
local
CVE-2023-2640HIGH02 Nov 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISK
open
GitHub PoC
jakedmurphy1/CVE-2023-46954
CVE-2023-46954CRITICAL02 Nov 2023
SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacke
48RISK
open
GitHub PoC
sajaljat/CVE-2023-46980
CVE-2023-46980CRITICAL02 Nov 2023
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privile
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-536002 Nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC8
Checker for CVE-2023-22518 vulnerability on Confluence
CVE-2023-22518CRITICALunder attackransomware02 Nov 2023
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALunder attackransomware02 Nov 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
GitHub PoC7
nvansluis/test_cve-2023-46747
CVE-2023-46747CRITICALunder attackransomware02 Nov 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-536002 Nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
local
CVE-2023-32629HIGH02 Nov 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISK
open
GitHub PoC
SideCopy APT Group exploits CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware01 Nov 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack01 Nov 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC208
exploit for f5-big-ip RCE cve-2023-46747
CVE-2023-46747CRITICALunder attackransomware01 Nov 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALunder attackransomware01 Nov 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
GitHub PoC2
maniak-academy/Mitigate-CVE-2023-46747
CVE-2023-46747CRITICALunder attackransomware01 Nov 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
GitHub PoC
CVE-2023-46747 Criticle Auth Bypass
CVE-2023-46747CRITICALunder attackransomware01 Nov 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
GitHub PoC1
A simple bash script that exploits CVE-2021-22205 against vulnerable instances of gitlab
CVE-2021-22205CRITICALunder attackransomware01 Nov 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware01 Nov 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack31 Oct 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
client-side
CVE-2020-9802HIGH31 Oct 2023
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa
41RISK
open
GitHub PoC
4xolotl/CVE-2018-15473
CVE-2018-15473MEDIUM31 Oct 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC14
BoltWire v6.03 vulnerable to "Improper Access Control"
CVE-2023-46501CRITICAL31 Oct 2023
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view a
48RISK
open
GitHub PoC61
Improper Authorization Vulnerability in Confluence Data Center and Server
CVE-2023-22518CRITICALunder attackransomware31 Oct 2023
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open
GitHub PoC1
EXPLOIT FOR CVE-2014-6271
CVE-2014-6271CRITICALunder attack31 Oct 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Metasploit600
Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
CVE-2023-22518CRITICALunder attackransomware31 Oct 2023
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open
previouspage 452 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.