Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,449 exploits
Exploit-DB
Label Studio 1.5.0 - Authenticated Server Side Request Forgery (SSRF)
CVE-2022-36551webappspython28 Mar 2023
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.
23RISK
open
VulnCheck XDB
infoleak
CVE-2022-24716HIGH27 Mar 2023
Path traversal in Icinga Web 2
78RISK
open
GitHub PoC
PoC for CVE-2022-39952 affecting Fortinet FortiNAC.
CVE-2022-39952CRITICAL27 Mar 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISK
open
Exploit-DB
FortiOS_ FortiProxy_ FortiSwitchManager v7.2.1 - Authentication Bypass
CVE-2022-40684CRITICALunder attackransomwarewebappsmultiple27 Mar 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
CVE-2022-44877CRITICALunder attack27 Mar 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-44877CRITICALunder attack27 Mar 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-28432HIGHunder attack27 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39285HIGHwebappsphp27 Mar 2023
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open
VulnCheck XDB
initial-access
CVE-2022-39952CRITICAL27 Mar 2023
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8
85RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39290HIGHwebappsphp27 Mar 2023
CSRF key bypass using HTTP methods in zoneminder
41RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39291MEDIUMwebappsphp27 Mar 2023
Denial of service through logs in zoneminder
33RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-28434HIGHunder attack27 Mar 2023
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISK
open
Exploit-DBVexDay Proof
Grafana <=6.2.4 - HTML Injection
CVE-2019-13068webappstypescript27 Mar 2023
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISK
open
GitHub PoC2
通过vulhub的复现过程实现了,基本的批量检测。比较垃圾但是勉强能用
CVE-2023-28432HIGHunder attack27 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC319
EXP for CVE-2023-28434 MinIO unauthorized to RCE
CVE-2023-28434HIGHunder attack27 Mar 2023
MinIO is vulnerable to privilege escalation on Linux/MacOS
71RISK
open
GitHub PoC3
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24716HIGH27 Mar 2023
Path traversal in Icinga Web 2
78RISK
open
VulnCheck XDB
initial-access
CVE-2019-1653HIGHunder attack26 Mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
GitHub PoC
pumpkinpiteam/CVE-2022-24716
CVE-2022-24716HIGH26 Mar 2023
Path traversal in Icinga Web 2
78RISK
open
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL26 Mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL26 Mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC3
Unauthenticated RCE in Open Web Analytics version <1.7.4
CVE-2022-2463726 Mar 2023
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open
GitHub PoC3
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 Mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC1
pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL26 Mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack26 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC1
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information.
CVE-2019-1653HIGHunder attack26 Mar 2023
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-24716HIGH26 Mar 2023
Path traversal in Icinga Web 2
78RISK
open
GitHub PoC5
0xNahim/CVE-2023-23752
CVE-2023-23752MEDIUMunder attack26 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Exploit-DBVexDay Proof
Translatepress Multilinugal WordPress plugin < 2.3.3 - Authenticated SQL Injection
CVE-2022-3141webappsphp25 Mar 2023
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISK
open
GitHub PoC4
Joomla Unauthorized Access Vulnerability (CVE-2023-23752) Dockerized
CVE-2023-23752MEDIUMunder attack25 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack25 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
previouspage 514 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.