Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
77,302 exploits
VulnCheck XDB
local
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open ↗GitHub PoC★ 179
fortra/CVE-2023-28252
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗GitHub PoC★ 14
A Python script for generating exploits targeting CVE-2022-4510 RCE Binwalk. It supports SSH, command execution, and reverse shell options. Exploits are saved in PNG format. Ideal for testing and demonstrations.
Path Traversal in binwalk
46RISK
open ↗VulnCheck XDB
infoleak
NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access
56RISK
open ↗GitHub PoC★ 13
This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id: CVE-2022-42889.
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open ↗GitHub PoC
ps-interactive/lab_cve-2021-4034-polkit-emulation-and-detection
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
initial-access
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open ↗Exploit-DB
Azure Apache Ambari 2302250400 - Spoofing
Azure Apache Ambari Spoofing Vulnerability
33RISK
open ↗Exploit-DB
PrestaShop Winbiz Payment module - Improper Limitation of a Pathname to a Restricted Directory
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download
41RISK
open ↗GitHub PoC
manavvedawala/CVE-2023-32243-proof-of-concept
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open ↗VulnCheck XDB
infoleak
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files
50RISK
open ↗GitHub PoC
An exploit for the Nibbles manager version 4.0.3. This exploit allows RCE to be performed.
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open ↗VulnCheck XDB
infoleak
packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory trav
56RISK
open ↗Exploit-DB
Microsoft SharePoint Enterprise Server 2016 - Spoofing
Microsoft SharePoint Server Spoofing Vulnerability
41RISK
open ↗Metasploit600
MagnusBilling application unauthenticated Remote Command Execution.
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open ↗Exploit-DB
Windows 11 22h2 - Kernel Privilege Elevation
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 2
Tools for working with ImageMagick to handle arbitrary file read vulnerabilities. Generate, read, and apply profile information to PNG files using a command-line interface.
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open ↗GitHub PoC★ 8
SPIP Vulnerability Scanner - CVE-2023-27372 Detector
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open ↗VulnCheck XDB
local
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open ↗VulnCheck XDB
initial-access
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open ↗GitHub PoC
pashayogi/CVE-2023-22809
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open ↗VulnCheck XDB
initial-access
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISK
open ↗GitHub PoC★ 1
Based on the x.pl exploit/loader script for CVE-2009-1151
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISK
open ↗GitHub PoC★ 10
An exploit for CVE-2018-5955 GitStack 2.3.10 Unauthenticated RCE
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISK
open ↗Exploit-DB
NCH Express Invoice - Clear Text Password Storage and Account Takeover
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
23RISK
open ↗GitHub PoC★ 1
Windows Network File System Remote exploit (DoS) PoC
Windows Network File System Remote Code Execution Vulnerability
70RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.