Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
GitHub PoC4
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Edit User functionality of the Microworld Technologies eScan Management Console (version 14.0.1400.2281).
CVE-2023-31703CRITICAL17 May 2023
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allo
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALunder attack17 May 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH17 May 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
GitHub PoC2
CVE-2023-31702 is an authenticated SQL Injection vulnerability discovered in MicroWorld Technologies eScan Management Console version 14.0.1400.2281.
CVE-2023-31702HIGH17 May 2023
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RISK
open
GitHub PoC
Exploit to cve-2023-1671. So there is a test and exploitation function. The test sends a ping request to the dnslog domain from the vulnerable site. If the ping passes, the vulnerability exists, if it doesn't, then cve-2023-1671 is missing. The exploit function, on the other hand, sends a request with your command to the server.
CVE-2023-1671CRITICALunder attack17 May 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
GitHub PoC24
PoC for CVE-2023-20126
CVE-2023-20126CRITICAL17 May 2023
Cisco SPA112 2-Port Phone Adapters Remote Command Execution Vulnerability
60RISK
open
Metasploit600
Delta Electronics InfraSuite Device Master Deserialization
CVE-2023-1133CRITICAL17 May 2023
CVE-2023-1133
75RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack16 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC51
Vulnerabilities Exploitation On Ubuntu 22.04
CVE-2023-0386HIGHunder attack16 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC11
POC for the CVE-2022-36944 vulnerability exploit
CVE-2022-36944CRITICAL16 May 2023
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There i
48RISK
open
VulnCheck XDB
infoleak
CVE-2017-1315616 May 2023
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISK
open
VulnCheck XDB
local
CVE-2023-32233HIGH16 May 2023
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RISK
open
VulnCheck XDB
local
CVE-2023-32233HIGH16 May 2023
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RISK
open
VulnCheck XDB
local
CVE-2023-32233HIGH16 May 2023
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RISK
open
GitHub PoC
school project
CVE-2019-15107CRITICALunder attackransomware15 May 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL15 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-25194HIGH15 May 2023
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RISK
open
VulnCheck XDB
local
CVE-2023-28206HIGHunder attack15 May 2023
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5,
76RISK
open
GitHub PoC8
Abusing CVE-2023-28206 to make something useful
CVE-2023-28206HIGHunder attack15 May 2023
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5,
76RISK
open
GitHub PoC1
Exploit script for CVE-2022-41544 - RCE in get-simple CMS
CVE-2022-41544HIGH15 May 2023
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RISK
open
GitHub PoC84
CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation
CVE-2023-32243CRITICAL15 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
Metasploit600
SolarView Compact unauthenticated remote command execution vulnerability.
CVE-2023-23333CRITICAL15 May 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open
GitHub PoC4
Akash7350/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack14 May 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC3
Exploit for CVE-2023-32243 - Unauthorized Account Takeover.
CVE-2023-32243CRITICAL14 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
VulnCheck XDB
local
CVE-2022-24481HIGH14 May 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
46RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL14 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack14 May 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack14 May 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
client-side
CVE-2022-30190HIGHunder attackransomware14 May 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1144714 May 2023
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
previouspage 499 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.