Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,332GitHub PoC 14,209VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
77,231 exploits
GitHub PoC★ 126
Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗VulnCheck XDB
initial-access
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open ↗VulnCheck XDB
initial-access
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗GitHub PoC
Wordpress CVE-2023-5360
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open ↗GitHub PoC★ 10
Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open ↗GitHub PoC
NestyF/SSH_Enum_CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗VulnCheck XDB
local
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISK
open ↗GitHub PoC
jakedmurphy1/CVE-2023-46954
SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacke
48RISK
open ↗GitHub PoC
sajaljat/CVE-2023-46980
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privile
48RISK
open ↗VulnCheck XDB
initial-access
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open ↗GitHub PoC★ 8
Checker for CVE-2023-22518 vulnerability on Confluence
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open ↗VulnCheck XDB
initial-access
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open ↗GitHub PoC★ 7
nvansluis/test_cve-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open ↗VulnCheck XDB
local
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISK
open ↗GitHub PoC
SideCopy APT Group exploits CVE-2023-38831
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗VulnCheck XDB
initial-access
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open ↗GitHub PoC★ 208
exploit for f5-big-ip RCE cve-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open ↗GitHub PoC★ 2
maniak-academy/Mitigate-CVE-2023-46747
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open ↗GitHub PoC
CVE-2023-46747 Criticle Auth Bypass
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open ↗GitHub PoC★ 1
A simple bash script that exploits CVE-2021-22205 against vulnerable instances of gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗VulnCheck XDB
initial-access
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
client-side
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa
41RISK
open ↗GitHub PoC
4xolotl/CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 14
BoltWire v6.03 vulnerable to "Improper Access Control"
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view a
48RISK
open ↗GitHub PoC★ 61
Improper Authorization Vulnerability in Confluence Data Center and Server
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open ↗GitHub PoC★ 1
EXPLOIT FOR CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Metasploit600
Atlassian Confluence Unauth JSON setup-restore Improper Authorization leading to RCE (CVE-2023-22518)
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.