Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,429GitHub PoC 14,270VulnCheck XDB 8,693Nuclei 4,299Metasploit 3,474✓ verified onlyrecentpopularrisk
77,453 exploits
GitHub PoC★ 8
CVE-2023-28343 POC exploit
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open ↗GitHub PoC★ 10
MiniO verify interface sensitive information disclosure vulnerability (CVE-2023-28432)
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 8
CVE-2022-42475 飞塔RCE漏洞 POC
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open ↗VulnCheck XDB
initial-access
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open ↗Exploit-DB
wkhtmltopdf 0.12.6 - Server Side Request Forgery
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by inje
28RISK
open ↗Exploit-DB
Bitbucket v7.0.0 - RCE
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open ↗VulnCheck XDB
initial-access
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISK
open ↗GitHub PoC★ 114
Exploit for CVE-2023-27532 against Veeam Backup & Replication
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISK
open ↗Exploit-DB
MAN-EAM-0003 V3.2.4 - XXE
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file uplo
56RISK
open ↗Exploit-DB
Linksys AX3200 V1.1.00 - Command Injection
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagn
46RISK
open ↗Metasploit600
Local Privilege Escalation via CVE-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open ↗Metasploit300
Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISK
open ↗GitHub PoC★ 1
betillogalvanfbc/POC-CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open ↗GitHub PoC★ 1
Mustafa1986/cve-2022-42475-Fortinet
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open ↗VulnCheck XDB
initial-access
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open ↗GitHub PoC★ 14
Python script for sending e-mails with CVE-2023-23397 payload using SMTP
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 25
Proof of Concept for CVE-2023-23397 in Python
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open ↗VulnCheck XDB
initial-access
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗GitHub PoC
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
48RISK
open ↗VulnCheck XDB
client-side
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISK
open ↗GitHub PoC
Mustafa1986/CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.