Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
GitHub PoC4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252309 May 2023
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC10
A PoC exploit for CVE-2019-15107 - Webmin Remote Code Execution
CVE-2019-15107CRITICALunder attackransomware08 May 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-37941MEDIUM08 May 2023
Apache Superset: Metadata db write access can lead to remote code execution
53RISK
open
VulnCheck XDB
infoleak
CVE-2015-835108 May 2023
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
GitHub PoC4
CVE-2023-0386 EXP
CVE-2023-0386HIGHunder attack08 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC11
Apache Superset Auth Bypass (CVE-2023-27524)
CVE-2023-27524HIGHunder attack08 May 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC2
WordPress Plugin Gwolle Guestbook 1.5.3 - Remote File Inclusion
CVE-2015-835108 May 2023
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
VulnCheck XDB
initial-access
CVE-2023-27524HIGHunder attack08 May 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware08 May 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
client-side
CVE-2023-23397CRITICALunder attack07 May 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC7
CVE-2023-23397 PoC
CVE-2023-23397CRITICALunder attack07 May 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
An exploit script for CVE-2022-28368 designed to make exploitation less annoying, made for a HTB machine
CVE-2022-2836807 May 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISK
open
GitHub PoC
CVE-2022-21907漏洞RCE PoC
CVE-2022-21907CRITICAL06 May 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC9
A PoC exploit for CVE-2017-5487 - WordPress User Enumeration.
CVE-2017-548706 May 2023
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack06 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC124
CVE-2023-0386 analysis and Exp
CVE-2023-0386HIGHunder attack06 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
initial-access
CVE-2022-21907CRITICAL06 May 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-25194HIGH05 May 2023
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RISK
open
GitHub PoC
User enumeration for CVE-2018-15473
CVE-2018-15473MEDIUM05 May 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC2
simple Python exploit using CVE-2018-7449 on embOS/IP FTP Server v3.22
CVE-2018-744905 May 2023
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RISK
open
Exploit-DB
Jedox 2022.4.2 - Code Execution via RPC Interfaces
CVE-2022-47879HIGHwebappsphp05 May 2023
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load a
41RISK
open
GitHub PoC420
CVE-2023-0386在ubuntu22.04上的提权
CVE-2023-0386HIGHunder attack05 May 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
Exploit-DB
Jedox 2020.2.5 - Remote Code Execution via Configurable Storage Path
CVE-2022-47878CRITICALwebappsphp05 May 2023
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica
60RISK
open
Exploit-DB
Jedox 2020.2.5 - Remote Code Execution via Executable Groovy-Scripts
CVE-2022-47876CRITICALwebappsphp05 May 2023
The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code v
48RISK
open
Exploit-DB
Jedox 2020.2.5 - Disclosure of Database Credentials via Improper Access Controls
CVE-2022-47874MEDIUMwebappsphp05 May 2023
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat
38RISK
open
GitHub PoC1
mclbn/docker-cve-2018-15473
CVE-2018-15473MEDIUM05 May 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Exploit-DB
Jedox 2022.4.2 - Remote Code Execution via Directory Traversal
CVE-2022-47875HIGHwebappsphp05 May 2023
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex
46RISK
open
Exploit-DB
Jedox 2020.2.5 - Stored Cross-Site Scripting in Log-Module
CVE-2022-47877CRITICALwebappsphp05 May 2023
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web
48RISK
open
Exploit-DB
Jedox 2022.4.2 - Disclosure of Database Credentials via Connection Checks
CVE-2022-47880MEDIUMwebappsphp05 May 2023
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users wi
33RISK
open
Metasploit600
TOTOLINK Wireless Routers unauthenticated remote command execution vulnerability.
CVE-2023-30013CRITICAL05 May 2023
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/s
68RISK
open
previouspage 501 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.