Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,302 exploits
GitHub PoC5
PoC exploit for file upload vulnerability in BoidCMS version <=2.0.0
CVE-2023-3883616 Aug 2023
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t
50RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL16 Aug 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-36899HIGH15 Aug 2023
ASP.NET Elevation of Privilege Vulnerability
63RISK
open
VulnCheck XDB
client-side
CVE-2023-3079HIGHunder attack15 Aug 2023
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corr
83RISK
open
VulnCheck XDB
local
CVE-2023-2640HIGH15 Aug 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISK
open
GitHub PoC130
mistymntncop/CVE-2023-3079
CVE-2023-3079HIGHunder attack15 Aug 2023
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC
GitHub repository for CVE-2023-3460 POC
CVE-2023-346015 Aug 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC4
CVE-2023-33242 PoC
CVE-2023-33242CRITICAL15 Aug 2023
Lindell17 TSS Abort Mishandling
48RISK
open
VulnCheck XDB
local
CVE-2020-0041HIGHunder attack14 Aug 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
GitHub PoC
This is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/zerologon_tester.py) and the tool evil-winrm to get a shell.
CVE-2020-1472MEDIUMunder attackransomware14 Aug 2023
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware14 Aug 2023
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC8
Local privilege escalation exploit for Android Binder bug CVE-2020-0041 (Pixel 3a)
CVE-2020-0041HIGHunder attack14 Aug 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
Metasploit600
Ivanti Avalanche MDM Buffer Overflow
CVE-2023-32560HIGH14 Aug 2023
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
GitHub PoC2
CVE-2022-44268_By_Kyokito
CVE-2022-44268MEDIUM13 Aug 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM13 Aug 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack13 Aug 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-34621CRITICAL12 Aug 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
GitHub PoC1
A PoC exploit for CVE-2021-34621 - WordPress Privilege Escalation
CVE-2021-34621CRITICAL12 Aug 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
GitHub PoC
CVE-2023-4174 PoC
CVE-2023-4174LOW11 Aug 2023
mooSocial mooStore cross site scripting
43RISK
open
GitHub PoC1
CVE-2023-33246 POC
CVE-2023-33246CRITICALunder attack11 Aug 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Aug 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALunder attack11 Aug 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
Exploit-DB
TP-Link Archer AX21 - Unauthenticated Command Injection
CVE-2023-1389HIGHunder attackremotehardware10 Aug 2023
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISK
open
GitHub PoC
yosef0x01/CVE-2023-21752
CVE-2023-21752HIGH10 Aug 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC3
Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527
CVE-2023-39526CRITICAL10 Aug 2023
PrestaShopSQL manager vulnerability (potential RCE)
48RISK
open
GitHub PoC65
mandiant/citrix-ioc-scanner-cve-2023-3519
CVE-2023-3519CRITICALunder attackransomware10 Aug 2023
Unauthenticated remote code execution
100RISK
open
VulnCheck XDB
client-side
CVE-2021-2503209 Aug 2023
PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
38RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864609 Aug 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC52
PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2
CVE-2023-38408CRITICAL09 Aug 2023
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-38408CRITICAL09 Aug 2023
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
previouspage 474 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.