Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,449 exploits
GitHub PoC1
RubXkuB/PoC-Metabase-CVE-2021-41277
CVE-2021-41277CRITICALunder attack24 Apr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC16
CVE-2023-1671-POC, based on dnslog platform
CVE-2023-1671CRITICALunder attack24 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
GitHub PoC
msd0pe-1/CVE-2023-31747
CVE-2023-31747HIGH24 Apr 2023
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISK
open
GitHub PoC3
Pre-Auth RCE in Sophos Web Appliance
CVE-2023-1671CRITICALunder attack23 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
GitHub PoC1
glen-pearson/ProxyLogon-CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware23 Apr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware23 Apr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-40799HIGHunder attack23 Apr 2023
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l
83RISK
open
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALunder attack23 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1609CRITICAL22 Apr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware22 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC55
Proof of Concept Exploit for PaperCut CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware22 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC1
Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.
CVE-2022-1609CRITICAL22 Apr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open
GitHub PoC12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC2
「💥」CVE-2022-4944: KodExplorer <= 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUM21 Apr 2023
kalcaddle KodExplorer cross-site request forgery
33RISK
open
GitHub PoC5
A simple python script to check if a service is vulnerable
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-1454MEDIUM21 Apr 2023
jeecg-boot qurestSql sql injection
60RISK
open
VulnCheck XDB
infoleak
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
CVE-2018-15473MEDIUM21 Apr 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
Metasploit300
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
CVE-2023-26876HIGH21 Apr 2023
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
36RISK
open
Exploit-DB
Microsoft Word 16.72.23040900 - Remote Code Execution (RCE)
CVE-2023-28311HIGHremotemultiple20 Apr 2023
Microsoft Word Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
Linux Kernel 6.2 - Userspace Processes To Enable Mitigation
CVE-2023-1998MEDIUMlocallinux20 Apr 2023
Spectre v2 SMT mitigations problem in Linux kernel
33RISK
open
GitHub PoC
A little demonstration of cve-2021-41773 on httpd docker containers
CVE-2021-41773HIGHunder attackransomware20 Apr 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DB
GDidees CMS 3.9.1 - Local File Disclosure
CVE-2023-27179HIGHwebappsphp20 Apr 2023
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RISK
open
Exploit-DBVexDay Proof
Bang Resto v1.0 - 'Multiple' SQL Injection
CVE-2023-29849HIGHwebappsphp20 Apr 2023
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice
41RISK
open
Exploit-DBVexDay Proof
Bang Resto v1.0 - Stored Cross-Site Scripting (XSS)
CVE-2023-29848MEDIUMwebappsphp20 Apr 2023
Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in
33RISK
open
Exploit-DB
File Replication Pro 7.5.0 - Privilege Escalation/Password reset due Incorrect Access Control
CVE-2023-26918CRITICALlocalwindows20 Apr 2023
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan
48RISK
open
VulnCheck XDB
initial-access
CVE-2020-1745320 Apr 2023
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
43RISK
open
GitHub PoC14
CVE-2023-21823 PoC
CVE-2023-21823HIGHunder attack20 Apr 2023
Windows Graphics Component Remote Code Execution Vulnerability
71RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware20 Apr 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 505 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.