Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,449 exploits
Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
CVE-2022-24630webappsphp30 Mar 2023
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh
28RISK
open
Exploit-DB
Dreamer CMS v4.0.0 - SQL Injection
CVE-2022-43128webappsmultiple30 Mar 2023
20RISK
open
Metasploit400
Rocket Software Unidata udadmin_server Stack Buffer Overflow in Password
CVE-2023-28502CRITICAL30 Mar 2023
Stack buffer overflow in UniRPC's udadmin_server service
75RISK
open
Exploit-DB
LISTSERV 17 - Insecure Direct Object Reference (IDOR)
CVE-2022-40319HIGHwebappscgi30 Mar 2023
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a
41RISK
open
Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
CVE-2022-24629CRITICALwebappsphp30 Mar 2023
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achie
60RISK
open
Metasploit600
Rocket Software Unidata udadmin_server Authentication Bypass
CVE-2023-28503CRITICAL30 Mar 2023
Authentication bypass in UniRPC's udadmin service
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-2812130 Mar 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISK
open
Exploit-DB
LISTSERV 17 - Reflected Cross Site Scripting (XSS)
CVE-2022-39195MEDIUMwebappscgi30 Mar 2023
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary
48RISK
open
Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
CVE-2022-24627CRITICALwebappsphp30 Mar 2023
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injec
68RISK
open
Exploit-DB
CrowdStrike Falcon AGENT 6.44.15806 - Uninstall without Installation Token
CVE-2022-2841LOWlocalwindows30 Mar 2023
CrowdStrike Falcon Uninstallation authorization
28RISK
open
GitHub PoC1
ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS
CVE-2023-26692MEDIUM30 Mar 2023
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RISK
open
GitHub PoC
turnernator1/Node.js-CVE-2017-5941
CVE-2017-594130 Mar 2023
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
Metasploit600
Nextcloud Workflows Remote Code Execution
CVE-2023-26482CRITICAL30 Mar 2023
Scope of workflow operations is not validated in nextcloud server
63RISK
open
Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
CVE-2022-24632webappsphp30 Mar 2023
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during f
28RISK
open
VulnCheck XDB
infoleak
CVE-2023-28432HIGHunder attack29 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
VulnCheck XDB
client-side
CVE-2023-23397CRITICALunder attack29 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
jacquesquail/CVE-2023-23397
CVE-2023-23397CRITICALunder attack29 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
0759104103/cd-CVE-2019-11932
CVE-2019-1193229 Mar 2023
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RISK
open
GitHub PoC10
CVE-2023-28432 MinIO敏感信息泄露检测脚本
CVE-2023-28432HIGHunder attack29 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
Exploit-DBVexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-1565HIGHwebappsphp29 Mar 2023
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RISK
open
GitHub PoC1
Full LPE Exploit for CVE-2019-5596 / FreeBSD-SA-19:02.fd
CVE-2019-559629 Mar 2023
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RISK
open
Exploit-DB
X-Skipper-Proxy v0.13.237 - Server Side Request Forgery (SSRF)
CVE-2022-38580CRITICALremotemultiple28 Mar 2023
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
53RISK
open
Exploit-DB
Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
CVE-2022-36551webappspython28 Mar 2023
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.
23RISK
open
Exploit-DB
ZKTeco ZEM/ZMM 8.88 - Missing Authentication
CVE-2022-42953HIGHwebappsjsp28 Mar 2023
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct r
41RISK
open
Exploit-DB
Tapo C310 RTSP server v1.3.0 - Unauthorised Video Stream Access
CVE-2022-37255HIGHremotehardware28 Mar 2023
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646
41RISK
open
Exploit-DB
OPSWAT Metadefender Core - Privilege Escalation
CVE-2022-32272webappsmultiple28 Mar 2023
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5
23RISK
open
Exploit-DB
ReQlogic v11.3 - Reflected Cross-Site Scripting (XSS)
CVE-2022-41441MEDIUMwebappsaspx28 Mar 2023
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts o
48RISK
open
Exploit-DB
Pega Platform 8.1.0 - Remote Code Execution (RCE)
CVE-2022-24082CRITICALwebappsmultiple28 Mar 2023
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Inte
53RISK
open
GitHub PoC
cyberdesu/Remote-Buffer-overflow-CVE-2003-0172
CVE-2003-017228 Mar 2023
Buffer overflow in openlog function for PHP 4.3.1 on Windows operating system, and possibly other OSes, allows remote at
28RISK
open
Exploit-DBVexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGHwebappsphp28 Mar 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISK
open
previouspage 513 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.