Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,401 exploits
GitHub PoC2
Analysis & Exploit
CVE-2023-22809HIGH20 Jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack20 Jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC2
POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability
CVE-2022-0847HIGHunder attack20 Jun 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC1
Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info
CVE-2021-42013CRITICALunder attackransomware20 Jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-2291119 Jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
Exploit-DB
WordPress Theme Medic v1.0.0 - Weak Password Recovery Mechanism for Forgotten Password
CVE-2020-11027MEDIUMwebappsphp19 Jun 2023
Password reset links invalidation issue in WordPress
38RISK
open
GitHub PoC69
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
CVE-2023-27372CRITICAL19 Jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL19 Jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware19 Jun 2023
Netlogon Elevation of Privilege Vulnerability
100RISK
open
Exploit-DB
Symantec SiteMinder WebAgent v12.52 - Cross-site scripting (XSS)
CVE-2023-23956MEDIUMwebappshardware19 Jun 2023
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISK
open
GitHub PoC
overgrowncarrot1/CVE-2021-22911
CVE-2021-2291119 Jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack18 Jun 2023
Openfire administration console authentication bypass
100RISK
open
GitHub PoC57
Openfire Console Authentication Bypass Vulnerability with RCE plugin
CVE-2023-32315HIGHunder attack18 Jun 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
client-side
CVE-2023-30777HIGH17 Jun 2023
WordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)
68RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676317 Jun 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC23
FortiOS 管理界面中的堆内存下溢导致远程代码执行
CVE-2023-25610CRITICAL17 Jun 2023
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0
53RISK
open
GitHub PoC7
CVE-2023-24078 for FuguHub / BarracudaDrive
CVE-2023-24078HIGH17 Jun 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISK
open
GitHub PoC1
CVE-2023-24078 for FuguHub / BarracudaDrive
CVE-2023-24078HIGH17 Jun 2023
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISK
open
Metasploit600
Rudder Server SQLI Remote Code Execution
CVE-2023-30625HIGH16 Jun 2023
rudder-server vulnerable to SQL Injection
58RISK
open
GitHub PoC6
Repository with everything I have tracking the impact of MOVEit CVE-2023-34362
CVE-2023-34362CRITICALunder attackransomware16 Jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-27997CRITICALunder attackransomware16 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27997CRITICALunder attackransomware16 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC134
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
CVE-2023-27997CRITICALunder attackransomware16 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC4
Joomla未授权访问漏洞
CVE-2023-23752MEDIUMunder attack16 Jun 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23333CRITICAL16 Jun 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open
GitHub PoC
CVE-2023-34600
CVE-2023-34600CRITICAL16 Jun 2023
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
53RISK
open
GitHub PoC27
POC FortiOS SSL-VPN buffer overflow vulnerability
CVE-2023-27997CRITICALunder attackransomware16 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC14
SolarView Compact through 6.00 downloader.php commands injection (RCE) nuclei-templates
CVE-2023-23333CRITICAL16 Jun 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open
GitHub PoC
In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite configurations in the file "login.xml" and cause the login page to crash.
CVE-2023-24709HIGH16 Jun 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack16 Jun 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
previouspage 490 / 2,581next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.