Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,299 exploits
VulnCheck XDB
local
CVE-2010-0232HIGHunder attack11 Sep 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISK
open
GitHub PoC
ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*
CVE-2023-35674HIGHunder attack11 Sep 2023
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RISK
open
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI
CVE-2023-015911 Sep 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
GitHub PoC
Development of an exploit for privilege escalation in Windows systems ( NT / 2k / XP / 2K3 / VISTA / 2k8 / 7 ) using the vulnerability CVE-2010-0232
CVE-2010-0232HIGHunder attack11 Sep 2023
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RISK
open
VulnCheck XDB
initial-access
CVE-2022-4063CRITICAL11 Sep 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISK
open
VulnCheck XDB
initial-access
CVE-2023-015911 Sep 2023
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676311 Sep 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC1
Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.
CVE-2018-1676311 Sep 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC2
Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
CVE-2022-4063CRITICAL11 Sep 2023
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RISK
open
GitHub PoC
caopengyan/CVE-2023-2825
CVE-2023-2825CRITICAL10 Sep 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack10 Sep 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
0xZon/CVE-2022-46169-Exploit
CVE-2022-46169CRITICALunder attack10 Sep 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-2825CRITICAL10 Sep 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack10 Sep 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
davidholiday/CVE-2007-4559
CVE-2007-4559CRITICAL10 Sep 2023
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISK
open
GitHub PoC
RCE PoC for Apache Commons Text vuln
CVE-2022-4288909 Sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-1389HIGHunder attack09 Sep 2023
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288909 Sep 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
simulation experiment of Curveball (CVE-2020-0601) attacks under ECQV implicit certificates with Windows-like verifiers
CVE-2020-0601HIGHunder attack09 Sep 2023
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
Exploit-DB
Axigen < 10.3.3.47_ 10.2.3.12 - Reflected XSS
CVE-2022-31470webappsmultiple08 Sep 2023
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12
50RISK
open
GitHub PoC9
A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak
CVE-2017-822508 Sep 2023
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RISK
open
GitHub PoC
Hikikan/CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware08 Sep 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34527HIGHunder attackransomware08 Sep 2023
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2017-822508 Sep 2023
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RISK
open
Exploit-DB
SPA-Cart eCommerce CMS 1.9.0.3 - SQL Injection
CVE-2023-4548MEDIUMwebappsphp08 Sep 2023
SPA-Cart eCommerce CMS GET Parameter search sql injection
38RISK
open
VulnCheck XDB
initial-access
CVE-2016-6366HIGHunder attack08 Sep 2023
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RISK
open
Exploit-DB
Techview LA-5570 Wireless Gateway Home Automation Controller - Multiple Vulnerabilities
CVE-2023-34723remotehardware08 Sep 2023
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
23RISK
open
GitHub PoC28
jakabakos/CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
CVE-2023-27524HIGHunder attack08 Sep 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
Exploit-DB
Wordpress Plugin Elementor 3.5.5 - Iframe Injection
CVE-2022-4953webappsphp08 Sep 2023
Elementor < 3.5.5 - Iframe Injection
23RISK
open
VulnCheck XDB
initial-access
CVE-2023-27524HIGHunder attack08 Sep 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
previouspage 466 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.