Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
GitHub PoC4
Akash7350/CVE-2021-22204
CVE-2021-22204MEDIUMunder attack14 May 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC6
Exploits for Tenda Ac8v4 stack-based overflow to Remote-Code Execution via Mipsel Ropping (CVE-2023-33669 - CVE-2023-33675)
CVE-2023-33669CRITICAL13 May 2023
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct
48RISK
open
Exploit-DB
FLEX 1080 < 1085 Web 1.6.0 - Denial of Service
CVE-2022-2591HIGHdosandroid13 May 2023
TEM FLEX-1085 reboot denial of service
41RISK
open
GitHub PoC1
poc
CVE-2023-32243CRITICAL13 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL13 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
GitHub PoC7
Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts
CVE-2021-3156HIGHunder attack13 May 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack13 May 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
raiden757/CVE-2020-17087
CVE-2020-17087HIGHunder attack13 May 2023
Windows Kernel Local Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
Exploit for grafana CVE-2021-43798
CVE-2021-43798HIGHunder attack12 May 2023
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack12 May 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
local
CVE-2022-38181HIGHunder attack12 May 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack12 May 2023
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack12 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC3
R0rt1z2/CVE-2022-38181
CVE-2022-38181HIGHunder attack12 May 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
GitHub PoC
A simple PoC for CVE-2022-46169 a.k.a Cacti Unauthenticated Command Injection, a vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti prior from version 1.2.17 to 1.2.22
CVE-2022-46169CRITICALunder attack12 May 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack11 May 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
Baron SameEdit Heap Overflow LPE 1-Day Exploit
CVE-2021-3156HIGHunder attack11 May 2023
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-15133HIGHunder attack10 May 2023
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC
0xSalle/cve-2018-15133
CVE-2018-15133HIGHunder attack10 May 2023
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack10 May 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-15133HIGHunder attack10 May 2023
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-22555HIGHunder attack10 May 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware10 May 2023
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
Ejecución de exploit de deserialización con CVE-2017-5941
CVE-2018-15133HIGHunder attack10 May 2023
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-0543CRITICALunder attack10 May 2023
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
GitHub PoC
Ejecución de exploit de deserialización con CVE-2017-5941
CVE-2017-594110 May 2023
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
GitHub PoC
A exploit for CVE-2017-5638. This exploit works on versions 2.3.5-2.3.31 and 2.5 – 2.5.10
CVE-2017-5638CRITICALunder attackransomware10 May 2023
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
Script of Network Security Project - Attack on CVE-2021-22555
CVE-2021-22555HIGHunder attack10 May 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC3
A PoC exploit for CVE-2008-5862 - Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410
CVE-2008-586210 May 2023
Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitra
23RISK
open
GitHub PoC4
redis未授权、redis_CVE-2022-0543检测利用二合一脚本
CVE-2022-0543CRITICALunder attack10 May 2023
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
previouspage 500 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.