Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,246 exploits
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALunder attack24 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
VulnCheck XDB
local
CVE-2023-29360HIGHunder attack24 Sep 2023
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2022-34753HIGH22 Sep 2023
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist
78RISK
open
GitHub PoC
DimaMend/cve-2022-42889-text4shell
CVE-2022-4288922 Sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288922 Sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
client-side
CVE-2023-4863HIGHunder attack21 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-38831HIGHunder attackransomware21 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM21 Sep 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
infoleak
CVE-2023-39361CRITICAL21 Sep 2023
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISK
open
GitHub PoC3
Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE-2023-38831HIGHunder attackransomware21 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC316
mistymntncop/CVE-2023-4863
CVE-2023-4863HIGHunder attack21 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC
Perform With Massive Juniper Remote Code Execution
CVE-2023-36844MEDIUMunder attack20 Sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-36844MEDIUMunder attack20 Sep 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware20 Sep 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
A PoC for CVE-2022-26134 for Educational Purposes and Security Research
CVE-2022-26134CRITICALunder attackransomware20 Sep 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
CVE-2023-42793CRITICALunder attackransomware19 Sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
local
CVE-2023-2640HIGH17 Sep 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware17 Sep 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
CVE: CVE-2022-0847
CVE-2022-0847HIGHunder attack17 Sep 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack17 Sep 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2023-32629HIGH17 Sep 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware17 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
ngothienan/CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware17 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC62
A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845
CVE-2023-36845CRITICALunder attack16 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC
futurezayka/CVE-2011-3192
CVE-2011-319216 Sep 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2011-319216 Sep 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open
VulnCheck XDB
local
CVE-2023-36845CRITICALunder attack16 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4060CRITICAL15 Sep 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL15 Sep 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
GitHub PoC5
WAGO Remote Exploit Tool for CVE-2023-1698
CVE-2023-1698CRITICAL15 Sep 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
previouspage 464 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.