Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
77,231 exploits
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL20 Oct 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack20 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware20 Oct 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
local
CVE-2023-36802HIGHunder attack20 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC4
CISCO CVE POC SCRIPT
CVE-2023-20198CRITICALunder attack20 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC6
1vere$k POC on the CVE-2023-20198
CVE-2023-20198CRITICALunder attack20 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864620 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC
reket99/Cisco_CVE-2023-20198
CVE-2023-20198CRITICALunder attack20 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC20
Confluence后台rce
CVE-2023-22515CRITICALunder attackransomware20 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
Trinadh465/frameworks_base_AOSP10_r33_CVE-2023-20963
CVE-2023-20963HIGHunder attack20 Oct 2023
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RISK
open
GitHub PoC1
Joomla Unauthenticated Information Disclosure (CVE-2023-23752) exploit
CVE-2023-23752MEDIUMunder attack20 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
yTxZx/CVE-2023-23752
CVE-2023-23752MEDIUMunder attack20 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
000Tonio/cve-2021-1675
CVE-2021-1675HIGHunder attackransomware19 Oct 2023
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC14
CVE-2023-36802 ITW case
CVE-2023-36802HIGHunder attack19 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
local
CVE-2023-36802HIGHunder attack19 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC11
CVE-2023-20198 PoC (!)
CVE-2023-20198CRITICALunder attack18 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC
Checker for CVE-2023-20198 , Not a full POC Just checks the implementation and detects if hex is in response or not
CVE-2023-20198CRITICALunder attack18 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC2
This script can identify if Cisco IOS XE devices are vulnerable to CVE-2023-20198
CVE-2023-20198CRITICALunder attack18 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC20
CVE-2023-20198 Checkscript
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC
raystr-atearedteam/CVE-2023-20198-checker
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware17 Oct 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
emomeni/Simple-Ansible-for-CVE-2023-20198
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC1
cisco-CVE-2023-20198-tester
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC33
CVE-2023-20198 & 0Day Implant Scanner
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
local
CVE-2023-4911HIGHunder attack17 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864617 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHunder attack17 Oct 2023
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC43
Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.
CVE-2023-4911HIGHunder attack17 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC
Proxyshell for Exploiting CVE-2021-34473
CVE-2021-34473CRITICALunder attackransomware17 Oct 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC80
检测域内常见一把梭漏洞,包括:NoPac、ZeroLogon、CVE-2022-26923、PrintNightMare
CVE-2022-26923HIGHunder attack17 Oct 2023
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
previouspage 457 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.