Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,587cataloged exploits
35,644CVEs with public exploitation
24,695lab-tested
77,449 exploits
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALunder attack26 Apr 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack26 Apr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC19
A collection of resources and information about CVE-2023-2033
CVE-2023-2033HIGHunder attack26 Apr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC2
A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.
CVE-2022-0847HIGHunder attack26 Apr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC25
CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5
CVE-2023-22621CRITICAL25 Apr 2023
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RISK
open
GitHub PoC
Check for CVE-2014-0160
CVE-2014-0160HIGHunder attack25 Apr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
ShyTangerine/cve-2021-26855
CVE-2021-26855CRITICALunder attackransomware25 Apr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALunder attack25 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-908125 Apr 2023
20RISK
open
GitHub PoC
2022 Spring Prof. 謝續平
CVE-2022-21907CRITICAL25 Apr 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack25 Apr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware25 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27524HIGHunder attack25 Apr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware25 Apr 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC8
Exploit for Papercut CVE-2023-27350. [+] Reverse shell [+] Mass checking
CVE-2023-27350CRITICALunder attackransomware25 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Exploit-DB
KodExplorer 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUMwebappsphp25 Apr 2023
kalcaddle KodExplorer cross-site request forgery
33RISK
open
GitHub PoC1
Fix URL containing SPACES after Apache upgrade CVE-2023-25690
CVE-2023-25690CRITICAL25 Apr 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
Exploit-DB
PaperCut NG/MG 22.0.4 - Authentication Bypass
CVE-2023-27350CRITICALunder attackransomwarewebappsmultiple25 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC9
Perform With Mass Exploits In WSO Management.
CVE-2022-29464CRITICALunder attackransomware25 Apr 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC113
Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset
CVE-2023-27524HIGHunder attack25 Apr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
Exploit-DB
Sophos Web Appliance 4.3.10.4 - Pre-auth command injection
CVE-2023-1671CRITICALunder attackwebappsphp25 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
GitHub PoC
UnrealIRCd 3.2.8.1 backdoor command execution exploit in Python 3 (CVE-2010-2075).
CVE-2010-207525 Apr 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open
Metasploit300
Apache Superset Signed Cookie Priv Esc
CVE-2023-27524HIGHunder attack25 Apr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-22621CRITICAL25 Apr 2023
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RISK
open
Metasploit600
invscout RPM Privilege Escalation
CVE-2023-28528HIGH24 Apr 2023
IBM AIX command execution
36RISK
open
VulnCheck XDB
infoleak
CVE-2021-41277CRITICALunder attack24 Apr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC
andyhsu024/CVE-2021-29447
CVE-2021-29447HIGH24 Apr 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC
msd0pe-1/CVE-2023-31747
CVE-2023-31747HIGH24 Apr 2023
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALunder attack24 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
GitHub PoC13
CVE-2023-22894
CVE-2023-22894CRITICAL24 Apr 2023
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RISK
open
previouspage 504 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.