Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,286 exploits
GitHub PoC
futurezayka/CVE-2011-3192
CVE-2011-319216 Sep 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2011-319216 Sep 2023
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL15 Sep 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-4060CRITICAL15 Sep 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISK
open
GitHub PoC5
WAGO Remote Exploit Tool for CVE-2023-1698
CVE-2023-1698CRITICAL15 Sep 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
GitHub PoC8
Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE
CVE-2022-4060CRITICAL15 Sep 2023
User Post Gallery <= 2.19 - Unauthenticated RCE
75RISK
open
GitHub PoC
Anthony1500/CVE-2022-40684
CVE-2022-40684CRITICALunder attackransomware14 Sep 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALunder attackransomware14 Sep 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1000861CRITICALunder attack13 Sep 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
Metasploit600
Themebleed- Windows 11 Themes Arbitrary Code Execution CVE-2023-38146
CVE-2023-38146HIGH13 Sep 2023
Windows Themes Remote Code Execution Vulnerability
48RISK
open
Metasploit600
Craft CMS unauthenticated Remote Code Execution (RCE)
CVE-2023-41892CRITICAL13 Sep 2023
Craft CMS Remote Code Execution vulnerability
85RISK
open
GitHub PoC
CVE-2018-1000861 Exploit
CVE-2018-1000861CRITICALunder attack13 Sep 2023
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RISK
open
GitHub PoC1
CVE-2023-43481
CVE-2023-43481CRITICAL13 Sep 2023
An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote att
48RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware12 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware12 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC3
Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability
CVE-2023-38831HIGHunder attackransomware12 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC9
CVE-2023-38831 WinRaR Exploit Generator
CVE-2023-38831HIGHunder attackransomware12 Sep 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI
CVE-2023-015911 Sep 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
CVE-2022-4063CRITICAL11 Sep 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676311 Sep 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4063CRITICAL11 Sep 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISK
open
VulnCheck XDB
initial-access
CVE-2023-015911 Sep 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
GitHub PoC
Development of an exploit for privilege escalation in Windows systems ( NT / 2k / XP / 2K3 / VISTA / 2k8 / 7 ) using the vulnerability CVE-2010-0232
CVE-2010-0232HIGHunder attack11 Sep 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISK
open
GitHub PoC
ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*
CVE-2023-35674HIGHunder attack11 Sep 2023
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RISK
open
VulnCheck XDB
local
CVE-2010-0232HIGHunder attack11 Sep 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISK
open
GitHub PoC1
Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.
CVE-2018-1676311 Sep 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
caopengyan/CVE-2023-2825
CVE-2023-2825CRITICAL10 Sep 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
GitHub PoC
0xZon/CVE-2022-46169-Exploit
CVE-2022-46169CRITICALunder attack10 Sep 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack10 Sep 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack10 Sep 2023
Unauthenticated Command Injection
100RISK
open
previouspage 465 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.