Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,449 exploits
Metasploit300
Jasmin Ransomware Web Server Unauthenticated SQL Injection
CVE-2025-6095MEDIUM08 Apr 2023
codesiddhant Jasmin Ransomware checklogin.php sql injection
28RISK
open
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2022-43939HIGHunder attackwebappsjsp08 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open
Exploit-DBVexDay Proof
Joomla! v4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMunder attackwebappsphp08 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Exploit-DB
Altenergy Power Control Software C1.2.5 - OS command injection
CVE-2023-28343webappshardware08 Apr 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
Exploit-DB
Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
CVE-2023-0669HIGHunder attackransomwarewebappsjava08 Apr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
Exploit-DB
Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)
CVE-2022-0020MEDIUMwebappsmultiple08 Apr 2023
Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface
33RISK
open
Exploit-DB
Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
CVE-2022-25630MEDIUMwebappsmultiple08 Apr 2023
An authenticated user can embed malicious content with XSS into the admin group policy page.
33RISK
open
Exploit-DB
Icinga Web 2.10 - Arbitrary File Disclosure
CVE-2022-24716HIGHwebappsphp08 Apr 2023
Path traversal in Icinga Web 2
78RISK
open
Exploit-DB
ENTAB ERP 1.0 - Username PII leak
CVE-2022-30076MEDIUMwebappsasp08 Apr 2023
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames
33RISK
open
Exploit-DB
pfsenseCE v2.6.0 - Anti-brute force protection bypass
CVE-2023-27100CRITICALremotehardware08 Apr 2023
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open
Exploit-DB
FortiRecorder 6.4.3 - Denial of Service
CVE-2022-41333MEDIUMdoshardware08 Apr 2023
An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below
33RISK
open
Exploit-DB
Microsoft Excel 365 MSO (Version 2302 Build 16.0.16130.20186) 64-bit - Remote Code Execution (RCE)
CVE-2023-23399HIGHremotemultiple08 Apr 2023
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
X2CRM v6.6/6.9 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2022-48178MEDIUMwebappsphp08 Apr 2023
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via
33RISK
open
Exploit-DB
ZCBS/ZBBS/ZPBS v4.14k - Reflected Cross-Site Scripting (XSS)
CVE-2023-26692MEDIUMwebappscgi08 Apr 2023
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RISK
open
GitHub PoC
Ge-Per/Scanner-CVE-2023-23752
CVE-2023-23752MEDIUMunder attack08 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Exploit-DB
Adobe Connect 11.4.5 - Local File Disclosure
CVE-2023-22232MEDIUMwebappsmultiple08 Apr 2023
Adobe Connect Improper Access Control Security feature bypass
70RISK
open
GitHub PoC
jedai47/cve-2018-17182
CVE-2018-1718207 Apr 2023
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
Exploit-DB
NotrinosERP 0.7 - Authenticated Blind SQL Injection
CVE-2023-24788webappsphp07 Apr 2023
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RISK
open
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-727307 Apr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISK
open
GitHub PoC1
POC,EXP,chatGPT for me,只能给一些思路,全部不可用
CVE-2022-21306CRITICAL07 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
48RISK
open
VulnCheck XDB
infoleak
CVE-2020-6287CRITICALunder attack07 Apr 2023
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC
jedai47/CVE-2017-16994
CVE-2017-1699407 Apr 2023
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISK
open
GitHub PoC2
POC,EXP,chatGPT for me
CVE-2022-45047CRITICAL07 Apr 2023
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RISK
open
Exploit-DB
IBM Aspera Faspex 4.4.1 - YAML deserialization (RCE)
CVE-2022-47986CRITICALunder attackransomwareremotemultiple07 Apr 2023
IBM Aspera Faspex code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack07 Apr 2023
Unauthenticated Command Injection
100RISK
open
Exploit-DB
MAC 1200R - Directory Traversal
CVE-2021-27825HIGHwebappshardware07 Apr 2023
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-stati
41RISK
open
GitHub PoC
Checker help to verify created account or find it's mandat
CVE-2020-6287CRITICALunder attack07 Apr 2023
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
Exploit-DB
Wondershare Dr Fone 12.9.6 - Privilege Escalation
CVE-2023-27010HIGHlocalwindows07 Apr 2023
Wondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability all
41RISK
open
GitHub PoC2
DarokNET/CVE-2023-27100
CVE-2023-27100CRITICAL07 Apr 2023
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open
Exploit-DB
Docker based datastores for IBM Instana 241-2 243-0 - No Authentication
CVE-2023-27290CRITICALremotemultiple07 Apr 2023
IBM Observability with Instana missing authentication
48RISK
open
previouspage 508 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.