Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,449 exploits
Exploit-DB
NVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle
CVE-2022-34668CRITICALremotepython25 Mar 2023
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma
48RISK
open
Exploit-DB
ImpressCMS v1.4.3 - Authenticated SQL Injection
CVE-2022-26986webappsphp25 Mar 2023
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RISK
open
Exploit-DBVexDay Proof
Abantecart v1.3.2 - Authenticated Remote Code Execution
CVE-2022-26521webappsphp25 Mar 2023
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RISK
open
Exploit-DBVexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
CVE-2021-46360webappsphp25 Mar 2023
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RISK
open
GitHub PoC1
a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)
CVE-2019-0708CRITICALunder attackransomware25 Mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack25 Mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DB
DLink DIR 819 A1 - Denial of Service
CVE-2022-40946HIGHdoshardware25 Mar 2023
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack25 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Exploit-DB
System Mechanic v15.5.0.61 - Arbitrary Read/Write
CVE-2018-5701localwindows25 Mar 2023
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RISK
open
GitHub PoC
Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH25 Mar 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISK
open
Exploit-DBVexDay Proof
SimpleMachinesForum v2.1.1 - Authenticated Remote Code Execution
CVE-2022-26982webappsphp25 Mar 2023
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
23RISK
open
GitHub PoC
Brandaoo/CVE-2014-6271
CVE-2014-6271CRITICALunder attack25 Mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Exploit-DB
Password Manager for IIS v2.0 - XSS
CVE-2022-36664MEDIUMwebappsasp25 Mar 2023
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL
33RISK
open
Exploit-DBVexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
CVE-2022-26149webappsphp25 Mar 2023
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISK
open
Exploit-DBVexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142webappsphp25 Mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISK
open
Exploit-DB
_camp_ Raspberry Pi camera server 1.0 - Authentication Bypass
CVE-2022-37109CRITICALwebappspython25 Mar 2023
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access
60RISK
open
GitHub PoC1
RSA NetWitness Platform EDR Agent / Incorrect Access Control - Code Execution
CVE-2022-4752924 Mar 2023
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Wi
23RISK
open
VulnCheck XDB
infoleak
CVE-2023-28432HIGHunder attack24 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-28432HIGHunder attack24 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL24 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack24 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-28432HIGHunder attack24 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC15
CVE-2023-28432 POC
CVE-2023-28432HIGHunder attack24 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC37
MinIO敏感信息泄露漏洞批量扫描poc&exp
CVE-2023-28432HIGHunder attack24 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC7
CVE-2023-28432,minio未授权访问检测工具
CVE-2023-28432HIGHunder attack24 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
CVE-2023-23397 powershell patch script for Windows 10 and 11
CVE-2023-23397CRITICALunder attack24 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
An exploitation demo of Outlook Elevation of Privilege Vulnerability
CVE-2023-23397CRITICALunder attack24 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC94
Joomla! < 4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMunder attack24 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC6
test of exploit for CVE-2023-21716
CVE-2023-21716CRITICAL24 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC8
CVE-2023-28343 POC exploit
CVE-2023-2834323 Mar 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
previouspage 515 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.