Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
77,231 exploits
GitHub PoC41
Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)
CVE-2023-20198CRITICALunder attack23 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC33
This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273
CVE-2023-20198CRITICALunder attack23 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC42
CVE-2013-4786 Go exploitation tool
CVE-2013-478623 Oct 2023
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RISK
open
GitHub PoC
Python script get image from Hikvision camera with CVE-2017-7921 vulnerability
CVE-2017-7921CRITICALunder attack23 Oct 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
infoleak
CVE-2013-478623 Oct 2023
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack23 Oct 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
local
CVE-2023-36802HIGHunder attack23 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack23 Oct 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack22 Oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware22 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC1
haingn/HIK-CVE-2021-36260-Exploit
CVE-2021-36260CRITICALunder attack22 Oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-33044CRITICALunder attack22 Oct 2023
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC3
haingn/LoHongCam-CVE-2021-33044
CVE-2021-33044CRITICALunder attack22 Oct 2023
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC
banyaksepuh/Mass-CVE-2021-3129-Scanner
CVE-2021-3129CRITICALunder attackransomware22 Oct 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
cve-2023-22515的python利用脚本
CVE-2023-22515CRITICALunder attackransomware21 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
ShivamDey/CVE-2021-23017
CVE-2021-2301721 Oct 2023
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware21 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
Nielk74/CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware21 Oct 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC3
CVE-2023-5360 Auto Shell Upload WordPress Royal Elementor 1.3.78 Shell Upload
CVE-2023-536021 Oct 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
ShivamDey/Samba-CVE-2007-2447-Exploit
CVE-2007-244721 Oct 2023
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL20 Oct 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL20 Oct 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
GitHub PoC36
PoC for CVE-2023-36802 Microsoft Kernel Streaming Service Proxy
CVE-2023-36802HIGHunder attack20 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC2
WAGO系统远程代码执行漏洞(CVE-2023-1698)
CVE-2023-1698CRITICAL20 Oct 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack20 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack20 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC3
yTxZx/CVE-2023-28432
CVE-2023-28432HIGHunder attack20 Oct 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC61
VMware Aria Operations for Logs CVE-2023-34051
CVE-2023-34051CRITICAL20 Oct 2023
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can
60RISK
open
GitHub PoC
deIndra/CVE-2023-1698
CVE-2023-1698CRITICAL20 Oct 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
GitHub PoC
reket99/Cisco_CVE-2023-20198
CVE-2023-20198CRITICALunder attack20 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
previouspage 456 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.