Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,449 exploits
GitHub PoC10
veritas501/CVE-2023-0386
CVE-2023-0386HIGHunder attack20 Apr 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
Exploit-DB
Linux Kernel 6.2 - Userspace Processes To Enable Mitigation
CVE-2023-1998MEDIUMlocallinux20 Apr 2023
Spectre v2 SMT mitigations problem in Linux kernel
33RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware20 Apr 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
client-side
CVE-2021-3158919 Apr 2023
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Sof
43RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-3992CRITICALunder attackransomware19 Apr 2023
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288918 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
Dima2021/cve-2022-42889-text4shell
CVE-2022-4288918 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack17 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC4
Reproduce CVE-2023-2033
CVE-2023-2033HIGHunder attack17 Apr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC4
randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE
CVE-2022-22963CRITICALunder attack17 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
msd0pe-1/CVE-2023-31714
CVE-2023-3171416 Apr 2023
Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.
23RISK
open
GitHub PoC8
POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption
CVE-2023-21716CRITICAL16 Apr 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL16 Apr 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-21839HIGHunder attack15 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-25135CRITICAL15 Apr 2023
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP reques
68RISK
open
GitHub PoC4
houqe/EXP_CVE-2018-19518
CVE-2018-1951815 Apr 2023
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISK
open
GitHub PoC18
CVE-2023-21839 Python版本
CVE-2023-21839HIGHunder attack15 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-44228CRITICALunder attackransomware15 Apr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware15 Apr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1951815 Apr 2023
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RISK
open
VulnCheck XDB
infoleak
CVE-2023-28432HIGHunder attack13 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
hh-hunter/ml-CVE-2023-1177
CVE-2023-1177CRITICAL13 Apr 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
GitHub PoC3
CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)
CVE-2022-38181HIGHunder attack13 Apr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
GitHub PoC
CHINA-china/MinIO_CVE-2023-28432_EXP
CVE-2023-28432HIGHunder attack13 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC7
CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)
CVE-2022-38181HIGHunder attack13 Apr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
GitHub PoC3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
CVE-2022-46169CRITICALunder attack13 Apr 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack13 Apr 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
local
CVE-2022-38181HIGHunder attack13 Apr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
VulnCheck XDB
initial-access
CVE-2023-1454MEDIUM13 Apr 2023
jeecg-boot qurestSql sql injection
60RISK
open
VulnCheck XDB
infoleak
CVE-2021-35250HIGH13 Apr 2023
Directory Transversal Vulnerability in Serv-U 15.3
61RISK
open
previouspage 506 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.