Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,528cataloged exploits
35,606CVEs with public exploitation
24,695lab-tested
77,302 exploits
Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution
CVE-2022-21907CRITICALremotewindows07 Jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
client-side
CVE-2023-346007 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
Exploit-DB
Microsoft Edge 114.0.1823.67 (64-bit) - Information Disclosure
CVE-2023-33145MEDIUMlocalmultiple06 Jul 2023
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
33RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack06 Jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Exploit-DB
Lost and Found Information System v1.0 - SQL Injection
CVE-2023-33592webappsphp06 Jul 2023
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lf
23RISK
open
GitHub PoC8
An eBPF program to detect attacks on CVE-2022-0847
CVE-2022-0847HIGHunder attack06 Jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM06 Jul 2023
Cross site scripting
70RISK
open
GitHub PoC35
Exploit for CVE-2023-3460. Unauthorized admin access for Ultimate Member plugin < v2.6.7
CVE-2023-346005 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL05 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack05 Jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-346005 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC6
This is a PoC for CVE-2023-27372 which spawns a fully interactive shell.
CVE-2023-27372CRITICAL05 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC2
CVE-2017-7921 EXPLOIT
CVE-2017-7921CRITICALunder attack04 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
This is the Updated Python3 exploit for CVE-2019-9053
CVE-2019-905304 Jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM04 Jul 2023
Cross site scripting
70RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack04 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
Exploit-DB
POS Codekop v2.0 - Authenticated Remote Code Execution (RCE)
CVE-2023-36348webappsphp03 Jul 2023
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware03 Jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL03 Jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
Exploit-DB
TP-Link TL-WR940N V4 - Buffer OverFlow
CVE-2023-36355doshardware03 Jul 2023
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6Cfg
35RISK
open
VulnCheck XDB
initial-access
CVE-2023-2834303 Jul 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
GitHub PoC4
Wordpress CVE-2023-32243
CVE-2023-32243CRITICAL03 Jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
Exploit-DB
FuguHub 8.1 - Remote Code Execution
CVE-2023-24078HIGHwebappsmultiple03 Jul 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISK
open
GitHub PoC3
Fix WinVerifyTrust Signature Validation Vulnerability, CVE-2013-3900, QID-378332
CVE-2013-3900MEDIUMunder attack03 Jul 2023
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
Exploit-DB
Sales of Cashier Goods v1.0 - Cross Site Scripting (XSS)
CVE-2023-36346webappsphp03 Jul 2023
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RISK
open
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 64-bit - Remote Code Execution (RCE)
CVE-2023-28285HIGHremotemultiple03 Jul 2023
Microsoft Office Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
WP AutoComplete 1.0.4 - Unauthenticated SQLi
CVE-2022-4297CRITICALwebappsphp03 Jul 2023
WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi
48RISK
open
Exploit-DB
Microsoft 365 MSO (Version 2305 Build 16.0.16501.20074) 32-bit - Remote Code Execution (RCE)
CVE-2023-33137HIGHremotemultiple03 Jul 2023
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-3710CRITICAL03 Jul 2023
Printer web page invalid command execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-3496003 Jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISK
open
previouspage 484 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.