Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,401 exploits
GitHub PoC
Exploit for CVE-2022-44136 for chcking security of your site
CVE-2022-44136CRITICAL15 Jun 2023
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISK
open
VulnCheck XDB
initial-access
CVE-2021-2464715 Jun 2023
Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login
38RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack15 Jun 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL15 Jun 2023
Code Injection in pyload/pyload
85RISK
open
GitHub PoC
Samba 3.0.20
CVE-2007-244715 Jun 2023
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC2
5rGJ5aCh5oCq5YW9/CVE-2023-32315exp
CVE-2023-32315HIGHunder attack15 Jun 2023
Openfire administration console authentication bypass
100RISK
open
GitHub PoC1
overgrowncarrot1/CVE-2023-0297
CVE-2023-0297CRITICAL15 Jun 2023
Code Injection in pyload/pyload
85RISK
open
GitHub PoC140
rce
CVE-2023-32315HIGHunder attack14 Jun 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-4642214 Jun 2023
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
GitHub PoC6
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
CVE-2023-20887CRITICALunder attack14 Jun 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open
Exploit-DBVexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
CVE-2023-0297CRITICALwebappspython14 Jun 2023
Code Injection in pyload/pyload
85RISK
open
GitHub PoC
ohnonoyesyes/CVE-2023-32315
CVE-2023-32315HIGHunder attack14 Jun 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack14 Jun 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware14 Jun 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
y0d3n/CVE-2014-0094
CVE-2014-009414 Jun 2023
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-20887CRITICALunder attack14 Jun 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-32315HIGHunder attack14 Jun 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-20887CRITICALunder attack13 Jun 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-2197813 Jun 2023
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-2986CRITICAL13 Jun 2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISK
open
GitHub PoC229
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
CVE-2023-20887CRITICALunder attack13 Jun 2023
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open
GitHub PoC
Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress in Python Version
CVE-2023-2986CRITICAL13 Jun 2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISK
open
GitHub PoC2
python program to exploit CVE-2023-21716
CVE-2023-21716CRITICAL13 Jun 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
Exploit-DB
Teachers Record Management System 1.0 - File Upload Type Validation
CVE-2023-3187MEDIUMwebappsphp13 Jun 2023
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
33RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack13 Jun 2023
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
Exploit-DBVexDay Proof
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
CVE-2023-3184LOWwebappsphp13 Jun 2023
SourceCodester Sales Tracker Management System cross site scripting
28RISK
open
GitHub PoC
Sonatype Nexus 3.21.01 - Remote Code Execution (Authenticated - Updated)
CVE-2020-10199HIGHunder attack13 Jun 2023
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
GitHub PoC
Python 2.7
CVE-2023-27350CRITICALunder attackransomware13 Jun 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-27350CRITICALunder attackransomware13 Jun 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
local
CVE-2023-20963HIGHunder attack12 Jun 2023
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RISK
open
previouspage 491 / 2,581next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.