Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,302 exploits
GitHub PoC
puckiestyle/cve-2023-27997
CVE-2023-27997CRITICALunder attackransomware23 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-3459823 Jun 2023
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files
50RISK
open
Exploit-DB
NCH Express Invoice - Clear Text Password Storage and Account Takeover
CVE-2020-11560localwindows23 Jun 2023
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
23RISK
open
GitHub PoC1
Windows Network File System Remote exploit (DoS) PoC
CVE-2022-30136CRITICAL23 Jun 2023
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47076HIGHwebappsaspx22 Jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RISK
open
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47075HIGHwebappsaspx22 Jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RISK
open
VulnCheck XDB
infoleak
CVE-2023-27997CRITICALunder attackransomware22 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC1
imbas007/CVE-2023-27997-Check
CVE-2023-27997CRITICALunder attackransomware22 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-3614422 Jun 2023
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to downlo
50RISK
open
GitHub PoC34
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
CVE-2022-42475CRITICALunder attackransomware21 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-42475CRITICALunder attackransomware21 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
GitHub PoC
sonpt-afk/CVE-2018-11776-FIS
CVE-2018-11776HIGHunder attack21 Jun 2023
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack21 Jun 2023
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC2
PoC and exploit for CVE-2022-22965 Spring4Shell
CVE-2022-22965CRITICALunder attack20 Jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC19
Exploits for a heap overflow in MiniDLNA <=1.3.2 (CVE-2023-33476)
CVE-2023-33476CRITICAL20 Jun 2023
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by
48RISK
open
Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
CVE-2023-25187MEDIUMremotehardware20 Jun 2023
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RISK
open
Exploit-DB
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
CVE-2023-3320MEDIUMwebappsphp20 Jun 2023
The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,
33RISK
open
GitHub PoC1
Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info
CVE-2021-42013CRITICALunder attackransomware20 Jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC2
Analysis & Exploit
CVE-2023-22809HIGH20 Jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack20 Jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC2
POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability
CVE-2022-0847HIGHunder attack20 Jun 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-2868CRITICALunder attack20 Jun 2023
Remote Code injection in Barracuda Email Security Gateway
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack20 Jun 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Exploit-DBVexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
CVE-2023-27372CRITICALwebappsphp20 Jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
local
CVE-2023-22809HIGH20 Jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC11
cfielding-r7/poc-cve-2023-2868
CVE-2023-2868CRITICALunder attack20 Jun 2023
Remote Code injection in Barracuda Email Security Gateway
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-1454MEDIUM20 Jun 2023
jeecg-boot qurestSql sql injection
60RISK
open
Exploit-DBVexDay Proof
Super Socializer 7.13.52 - Reflected XSS
CVE-2023-2779MEDIUMwebappsphp20 Jun 2023
Super Socializer < 7.13.52 - Reflected XSS
48RISK
open
GitHub PoC69
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
CVE-2023-27372CRITICAL19 Jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL19 Jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
previouspage 487 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.