Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware29 May 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL29 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-21839HIGHunder attack29 May 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
Metasploit600
Dolibarr ERP/CRM Authenticated Code Injection
CVE-2023-30253HIGH29 May 2023
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instea
58RISK
open
GitHub PoC2
Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...
CVE-2023-32243CRITICAL29 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
GitHub PoC6
WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.
CVE-2020-0796CRITICALunder attackransomware29 May 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-28432HIGHunder attack27 May 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack27 May 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC2
Exploit for Bad Binder
CVE-2019-2215HIGHunder attack27 May 2023
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC2
Perfom With Massive Authentication Bypass In PaperCut MF/NG
CVE-2023-27350CRITICALunder attackransomware27 May 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC1
MinIO Information Disclosure Vulnerability scanner by metasploit
CVE-2023-28432HIGHunder attack27 May 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
Exploit-DBVexDay Proof
Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
CVE-2023-30145CRITICALwebappsruby26 May 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RISK
open
GitHub PoC1
PoC for login with password hash in STARFACE
CVE-2023-33243HIGH26 May 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RISK
open
GitHub PoC2
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行Exp
CVE-2022-22947CRITICALunder attack26 May 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
Metasploit600
Openfire authentication bypass with RCE plugin
CVE-2023-32315HIGHunder attack26 May 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack26 May 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC6
MStore API <= 3.9.2 - Authentication Bypass
CVE-2023-2732CRITICAL25 May 2023
MStore API <= 3.9.2 - Authentication Bypass
75RISK
open
VulnCheck XDB
initial-access
CVE-2018-133525 May 2023
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-2732CRITICAL25 May 2023
MStore API <= 3.9.2 - Authentication Bypass
75RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack25 May 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288925 May 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
Exploit-DB
SCM Manager 1.60 - Cross-Site Scripting Stored (Authenticated)
CVE-2023-33829MEDIUMwebappsmultiple25 May 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISK
open
VulnCheck XDB
initial-access
CVE-2023-21839HIGHunder attack25 May 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC140
GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab 16.0.0.
CVE-2023-2825CRITICAL25 May 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
GitHub PoC7
Camaleon CMS v2.7.0 contain a Server-Side Template Injection (SSTI) vulnerability
CVE-2023-30145CRITICAL25 May 2023
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RISK
open
GitHub PoC
Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function
CVE-2022-22963CRITICALunder attack25 May 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1472MEDIUMunder attackransomware25 May 2023
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-21587CRITICALunder attackransomware25 May 2023
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack25 May 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Exploit-DB
Seagate Central Storage 2015.0916 - Unauthenticated Remote Command Execution (Metasploit)
CVE-2020-6627CRITICALremotehardware25 May 2023
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS comman
53RISK
open
previouspage 496 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.