Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
Metasploit600
Barracuda ESG TAR Filename Command Injection
CVE-2023-2868CRITICALunder attack23 May 2023
Remote Code injection in Barracuda Email Security Gateway
100RISK
open
Exploit-DB
Apache Superset 2.0.0 - Authentication Bypass
CVE-2023-27524HIGHunder attackwebappsmultiple23 May 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1949223 May 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISK
open
Exploit-DBVexDay Proof
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
CVE-2022-41544HIGHwebappsphp23 May 2023
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL23 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
Exploit-DB
Yank Note v3.52.1 (Electron) - Arbitrary Code Execution
CVE-2023-31874HIGHlocalmultiple23 May 2023
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro
41RISK
open
VulnCheck XDB
initial-access
CVE-2019-1949223 May 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISK
open
VulnCheck XDB
initial-access
CVE-2019-1949223 May 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISK
open
VulnCheck XDB
initial-access
CVE-2023-25690CRITICAL22 May 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
GitHub PoC1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-596222 May 2023
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISK
open
GitHub PoC
Dockerized POC for CVE-2022-42889 Text4Shell
CVE-2022-4288922 May 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH22 May 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
CVE-2014-1812HIGHunder attackransomware22 May 2023
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288922 May 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL22 May 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack21 May 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
RCE Unauth in PyLoad <0.5.0b3.dev31
CVE-2023-0297CRITICAL21 May 2023
Code Injection in pyload/pyload
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack21 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
antisecc/CVE-2022-46169
CVE-2022-46169CRITICALunder attack21 May 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL21 May 2023
Code Injection in pyload/pyload
85RISK
open
VulnCheck XDB
infoleak
CVE-2022-24716HIGH20 May 2023
Path traversal in Icinga Web 2
78RISK
open
GitHub PoC
antisecc/CVE-2022-24716
CVE-2022-24716HIGH20 May 2023
Path traversal in Icinga Web 2
78RISK
open
VulnCheck XDB
local
CVE-2019-573620 May 2023
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH20 May 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
GitHub PoC
xiaosed/CVE-2023-29919
CVE-2023-29919CRITICAL19 May 2023
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
75RISK
open
GitHub PoC1
Golang implementation of ThinVNC exploit CVE-2019-17662. For educational purposes only.
CVE-2019-1766219 May 2023
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
GitHub PoC
Proof of Concept about a XSS Stored in SCM Manager 1.2 <= 1.60
CVE-2023-33829MEDIUM19 May 2023
A stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute
33RISK
open
VulnCheck XDB
infoleak
CVE-2023-29919CRITICAL19 May 2023
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because t
75RISK
open
GitHub PoC59
CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/
CVE-2023-21554CRITICAL18 May 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open
GitHub PoC4
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Edit User functionality of the Microworld Technologies eScan Management Console (version 14.0.1400.2281).
CVE-2023-31703CRITICAL17 May 2023
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RISK
open
previouspage 498 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.