Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,407GitHub PoC 14,247VulnCheck XDB 8,663Nuclei 4,287Metasploit 3,474✓ verified onlyrecentpopularrisk
77,348 exploits
Metasploit600
Rudder Server SQLI Remote Code Execution
rudder-server vulnerable to SQL Injection
58RISK
open ↗GitHub PoC★ 6
Repository with everything I have tracking the impact of MOVEit CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open ↗GitHub PoC★ 4
Joomla未授权访问漏洞
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 15
SolarView Compact through 6.00 downloader.php commands injection (RCE) nuclei-templates
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open ↗GitHub PoC★ 27
POC FortiOS SSL-VPN buffer overflow vulnerability
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open ↗GitHub PoC★ 134
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open ↗GitHub PoC
CVE-2023-34600
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
53RISK
open ↗VulnCheck XDB
initial-access
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open ↗GitHub PoC
Samba 3.0.20
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗GitHub PoC
Exploit for CVE-2022-44136 for chcking security of your site
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISK
open ↗GitHub PoC★ 2
5rGJ5aCh5oCq5YW9/CVE-2023-32315exp
Openfire administration console authentication bypass
100RISK
open ↗VulnCheck XDB
initial-access
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open ↗Exploit-DB✓ VexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Code Injection in pyload/pyload
85RISK
open ↗GitHub PoC
ohnonoyesyes/CVE-2023-32315
Openfire administration console authentication bypass
100RISK
open ↗GitHub PoC★ 6
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open ↗GitHub PoC★ 1
y0d3n/CVE-2014-0094
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISK
open ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
initial-access
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open ↗GitHub PoC
Sonatype Nexus 3.21.01 - Remote Code Execution (Authenticated - Updated)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open ↗GitHub PoC
Python 2.7
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open ↗VulnCheck XDB
initial-access
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISK
open ↗VulnCheck XDB
remote-with-credentials
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open ↗VulnCheck XDB
initial-access
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.