Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,302 exploits
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALunder attackransomware27 Jul 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware27 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC2
CVE-2021-3129 | Laravel Debug Mode Vulnerability
CVE-2021-3129CRITICALunder attackransomware27 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-346027 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC1
Exploit for the vulnerability of Ultimate Member Plugin.
CVE-2023-346027 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM26 Jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
GitHub PoC
Laravel RCE (CVE-2021-3129)
CVE-2021-3129CRITICALunder attackransomware26 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM26 Jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack26 Jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
CVE-2023-2640HIGH26 Jul 2023
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISK
open
Metasploit600
Greenshot .NET Deserialization Fileformat Exploit
CVE-2023-3463426 Jul 2023
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green
38RISK
open
Metasploit300
GameOver(lay) Privilege Escalation and Container Escape
CVE-2023-32629HIGH26 Jul 2023
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware26 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
simple program for joomla scanner CVE-2023-23752 with target list
CVE-2023-23752MEDIUMunder attack26 Jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC2
Python script to exploit PlaySMS before 1.4.3
CVE-2020-8644CRITICALunder attack25 Jul 2023
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-3864625 Jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC
Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE
CVE-2021-22204MEDIUMunder attack25 Jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-8644CRITICALunder attack25 Jul 2023
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RISK
open
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack25 Jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC46
A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.
CVE-2017-7921CRITICALunder attack24 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALunder attack24 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC1
CVE-2022-23305 Log4J JDBCAppender SQl injection POC
CVE-2022-23305CRITICAL24 Jul 2023
SQL injection in JDBC Appender in Apache Log4j V1
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3496024 Jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISK
open
GitHub PoC1
Learn what is BlueJam CVE-2017-0781
CVE-2017-078124 Jul 2023
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISK
open
GitHub PoC1
ImageMagick Arbitrary Read Files - CVE-2022-44268
CVE-2022-44268MEDIUM23 Jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
VulnCheck XDB
infoleak
CVE-2023-1177CRITICAL23 Jul 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
VulnCheck XDB
client-side
CVE-2021-2287322 Jul 2023
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg
50RISK
open
Metasploit600
Metabase Setup Token RCE
CVE-2023-3864622 Jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3496022 Jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISK
open
VulnCheck XDB
infoleak
CVE-2021-4191MEDIUM22 Jul 2023
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv
70RISK
open
previouspage 479 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.