Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,449 exploits
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-727307 Apr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISK
open
GitHub PoC
jedai47/cve-2018-17182
CVE-2018-1718207 Apr 2023
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack07 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC1
POC,EXP,chatGPT for me,只能给一些思路,全部不可用
CVE-2022-21306CRITICAL07 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
48RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project in PHP v 1.0 - SQL injection
CVE-2023-23156webappsphp06 Apr 2023
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid par
23RISK
open
Exploit-DB
Agilebio Lab Collector Electronic Lab Notebook v4.234 - Remote Code Execution (RCE)
CVE-2023-24217HIGHwebappsphp06 Apr 2023
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-0669HIGHunder attackransomware06 Apr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
GitHub PoC6
CVE-2023-22809 Linux Sudo
CVE-2023-22809HIGH06 Apr 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - Broken Access Control
CVE-2023-0963HIGHwebappsphp06 Apr 2023
SourceCodester Music Gallery Site POST Request Users.php access control
41RISK
open
Exploit-DBVexDay Proof
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40032CRITICALwebappsphp06 Apr 2023
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet
68RISK
open
GitHub PoC
qaisarafridi/cve-2021-3129
CVE-2021-3129CRITICALunder attackransomware06 Apr 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
Exploit-DB
modoboa 2.0.4 - Admin TakeOver
CVE-2023-0777HIGHwebappspython06 Apr 2023
Authentication Bypass by Primary Weakness in modoboa/modoboa
61RISK
open
GitHub PoC
BaconCriCRi/PoC-CVE-2022-4939-
CVE-2022-4939CRITICAL06 Apr 2023
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
48RISK
open
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
CVE-2023-0913MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System sql injection
33RISK
open
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
CVE-2023-0938MEDIUMwebappsphp06 Apr 2023
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RISK
open
Exploit-DBVexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
CVE-2023-0943MEDIUMwebappsphp06 Apr 2023
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISK
open
Exploit-DBVexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
CVE-2023-0961MEDIUMwebappsphp06 Apr 2023
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RISK
open
Exploit-DB
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-45701HIGHremotehardware06 Apr 2023
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISK
open
Exploit-DBVexDay Proof
Intern Record System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40347CRITICALwebappsphp06 Apr 2023
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack06 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Exploit-DB
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
CVE-2020-11798webappscgi06 Apr 2023
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before
50RISK
open
Exploit-DB
TitanFTP 2.0.1.2102 - Path traversal to Remote Code Execution (RCE)
CVE-2023-22629HIGHremotewindows06 Apr 2023
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RISK
open
VulnCheck XDB
initial-access
CVE-2023-28432HIGHunder attack06 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - Broken Authentication
CVE-2023-0905HIGHwebappsphp06 Apr 2023
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RISK
open
Exploit-DB
ABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root Access
CVE-2023-26609HIGHremotehardware06 Apr 2023
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin
53RISK
open
Exploit-DB
Dompdf 1.2.1 - Remote Code Execution (RCE)
CVE-2022-28368webappsphp06 Apr 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISK
open
Exploit-DB
POLR URL 2.3.0 - Shortener Admin Takeover
CVE-2021-21276CRITICALwebappsphp06 Apr 2023
Privilege escalation in Polr
48RISK
open
Exploit-DBVexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
CVE-2023-0916MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System Users.php access control
33RISK
open
GitHub PoC8
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
CVE-2023-0669HIGHunder attackransomware06 Apr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
Exploit-DBVexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
CVE-2023-0902LOWwebappsphp06 Apr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open
previouspage 509 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.