Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,449 exploits
GitHub PoC3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
CVE-2022-46169CRITICALunder attack13 Apr 2023
Unauthenticated Command Injection
100RISK
open
Metasploit600
ManageEngine ADManager Plus ChangePasswordAction Authenticated Command Injection
CVE-2023-29084HIGH12 Apr 2023
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy setti
58RISK
open
VulnCheck XDB
initial-access
CVE-2022-41800HIGH12 Apr 2023
Appliance mode iControl REST vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware12 Apr 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800
CVE-2022-1388CRITICALunder attackransomware12 Apr 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Metasploit400
Windows Common Log File System Driver (clfs.sys) Elevation of Privilege Vulnerability
CVE-2023-28252HIGHunder attackransomware11 Apr 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
nik0nz7/CVE-2020-14882
CVE-2020-14882CRITICALunder attack11 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Metasploit300
CVE-2023-21554 - QueueJumper - MSMQ RCE Check
CVE-2023-21554CRITICAL11 Apr 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open
GitHub PoC
FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow
CVE-2023-25234CRITICAL11 Apr 2023
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
53RISK
open
GitHub PoC
Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0
CVE-2022-46169CRITICALunder attack11 Apr 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack11 Apr 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-1454MEDIUM11 Apr 2023
jeecg-boot qurestSql sql injection
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack11 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack10 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
Rust-based exploit for the CVE-2022-22963 vulnerability
CVE-2022-22963CRITICALunder attack10 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Exploit-DB
Paradox Security Systems IPR512 - Denial Of Service
CVE-2023-24709HIGHdoshardware10 Apr 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISK
open
GitHub PoC3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
CVE-2023-30256MEDIUM10 Apr 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISK
open
Exploit-DB
Microsoft Edge (Chromium-based) Webview2 1.0.1661.34 - Spoofing
CVE-2023-24892HIGHlocalmultiple10 Apr 2023
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
41RISK
open
Exploit-DB
Online Computer and Laptop Store 1.0 - Remote Code Execution (RCE)
CVE-2023-1826MEDIUMwebappsphp10 Apr 2023
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
33RISK
open
GitHub PoC34
Perform With Mass Exploiter In Joomla 4.2.8.
CVE-2023-23752MEDIUMunder attack09 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288909 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack09 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
CVE-2023-28432HIGHunder attack09 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
Exploit-DB
Altenergy Power Control Software C1.2.5 - OS command injection
CVE-2023-28343webappshardware08 Apr 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
Metasploit300
Jasmin Ransomware Web Server Unauthenticated SQL Injection
CVE-2025-6095MEDIUM08 Apr 2023
codesiddhant Jasmin Ransomware checklogin.php sql injection
28RISK
open
Exploit-DB
Suprema BioStar 2 v2.8.16 - SQL Injection
CVE-2023-27167MEDIUMwebappsmultiple08 Apr 2023
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs
33RISK
open
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2022-43939HIGHunder attackwebappsjsp08 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open
Metasploit300
Jasmin Ransomware Web Server Unauthenticated Directory Traversal
CVE-2024-30851MEDIUM08 Apr 2023
Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive infor
28RISK
open
Exploit-DB
X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2022-48178MEDIUMwebappsphp08 Apr 2023
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via
33RISK
open
Exploit-DB
X2CRM v6.6/6.9 - Reflected Cross-Site Scripting (XSS) (Authenticated)
CVE-2022-48177MEDIUMwebappsphp08 Apr 2023
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v
33RISK
open
previouspage 507 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.