Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
77,449 exploits
GitHub PoC★ 3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
Unauthenticated Command Injection
100RISK
open ↗Metasploit600
ManageEngine ADManager Plus ChangePasswordAction Authenticated Command Injection
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy setti
58RISK
open ↗VulnCheck XDB
initial-access
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open ↗GitHub PoC★ 1
F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open ↗Metasploit400
Windows Common Log File System Driver (clfs.sys) Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open ↗GitHub PoC
nik0nz7/CVE-2020-14882
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗Metasploit300
CVE-2023-21554 - QueueJumper - MSMQ RCE Check
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open ↗GitHub PoC
FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
53RISK
open ↗GitHub PoC
Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0
Unauthenticated Command Injection
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗VulnCheck XDB
initial-access
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗GitHub PoC★ 1
Rust-based exploit for the CVE-2022-22963 vulnerability
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗Exploit-DB
Paradox Security Systems IPR512 - Denial Of Service
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISK
open ↗GitHub PoC★ 3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISK
open ↗Exploit-DB
Microsoft Edge (Chromium-based) Webview2 1.0.1661.34 - Spoofing
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
41RISK
open ↗Exploit-DB
Online Computer and Laptop Store 1.0 - Remote Code Execution (RCE)
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
33RISK
open ↗GitHub PoC★ 34
Perform With Mass Exploiter In Joomla 4.2.8.
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗Exploit-DB
Altenergy Power Control Software C1.2.5 - OS command injection
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open ↗Metasploit300
Jasmin Ransomware Web Server Unauthenticated SQL Injection
codesiddhant Jasmin Ransomware checklogin.php sql injection
28RISK
open ↗Exploit-DB
Suprema BioStar 2 v2.8.16 - SQL Injection
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs
33RISK
open ↗Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open ↗Metasploit300
Jasmin Ransomware Web Server Unauthenticated Directory Traversal
Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive infor
28RISK
open ↗Exploit-DB
X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via
33RISK
open ↗Exploit-DB
X2CRM v6.6/6.9 - Reflected Cross-Site Scripting (XSS) (Authenticated)
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.