Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,401 exploits
GitHub PoC77
CVE-2023-20963 PoC (Android WorkSource parcel/unparcel logic mismatch)
CVE-2023-20963HIGHunder attack12 Jun 2023
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RISK
open
GitHub PoC3
A script, written in golang. POC for CVE-2023-25157
CVE-2023-25157CRITICAL12 Jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL12 Jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack12 Jun 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
local
CVE-2023-20963HIGHunder attack12 Jun 2023
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RISK
open
VulnCheck XDB
infoleak
CVE-2022-3590MEDIUM12 Jun 2023
WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
48RISK
open
GitHub PoC3
omoknooni/CVE-2021-21311
CVE-2021-21311HIGHunder attack12 Jun 2023
SSRF in adminer
100RISK
open
GitHub PoC64
CVE-2023-34362: MOVEit Transfer Unauthenticated RCE
CVE-2023-34362CRITICALunder attackransomware12 Jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
Metasploit600
Apache NiFi H2 Connection String Remote Code Execution
CVE-2023-34468HIGH12 Jun 2023
Apache NiFi: Potential Code Injection with Database Services using H2
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL11 Jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
GitHub PoC14
GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)
CVE-2023-25157CRITICAL11 Jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
GitHub PoC1
lukinneberg/CVE-2023-2636
CVE-2023-263611 Jun 2023
AN_GradeBook <= 5.0.1 - Subscriber+ SQLi
23RISK
open
GitHub PoC
andyhsu024/CVE-2022-45025
CVE-2022-45025CRITICAL11 Jun 2023
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-25158CRITICAL11 Jun 2023
Unfiltered SQL Injection in Geotools
48RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-2227411 Jun 2023
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to
35RISK
open
VulnCheck XDB
infoleak
CVE-2023-25157CRITICAL10 Jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
GitHub PoC10
0x2458bughunt/CVE-2023-25157
CVE-2023-25157CRITICAL10 Jun 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
GitHub PoC2
DreamD2v/CVE-2023-31541
CVE-2023-31541CRITICAL10 Jun 2023
A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-34362CRITICALunder attackransomware09 Jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
GitHub PoC1
Thruk Monitoring Web Interface <= 3.06 vulnerable to CVE-2023-34096 (Path Traversal).
CVE-2023-34096MEDIUM09 Jun 2023
Thruk has Path Traversal Vulnerability in panorama.pm
45RISK
open
Exploit-DB
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
CVE-2021-24499webappsphp09 Jun 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
Metasploit300
MongoDB Ops Manager Diagnostic Archive Sensitive Information Retriever
CVE-2023-0342LOW09 Jun 2023
MongoDB Ops Manager may disclose sensitive information in Diagnostic Archive
23RISK
open
GitHub PoC138
MOVEit CVE-2023-34362
CVE-2023-34362CRITICALunder attackransomware09 Jun 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
GitHub PoC
antisecc/CVE-2018-16763
CVE-2018-1676309 Jun 2023
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-2986CRITICAL09 Jun 2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISK
open
GitHub PoC21
m-cetin/CVE-2023-29336
CVE-2023-29336HIGHunder attack09 Jun 2023
Win32k Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC6
Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress
CVE-2023-2986CRITICAL09 Jun 2023
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3496009 Jun 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISK
open
VulnCheck XDB
local
CVE-2023-29336HIGHunder attack09 Jun 2023
Win32k Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
hello4r1end/patch_CVE-2023-22809
CVE-2023-22809HIGH08 Jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
previouspage 492 / 2,581next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.