Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,533 exploits
Metasploit300
Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation
CVE-2023-2812122 Mar 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISK
open
Metasploit600
Local Privilege Escalation via CVE-2023-0386
CVE-2023-0386HIGHunder attack22 Mar 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC14
Python script for sending e-mails with CVE-2023-23397 payload using SMTP
CVE-2023-23397CRITICALunder attack22 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC25
Proof of Concept for CVE-2023-23397 in Python
CVE-2023-23397CRITICALunder attack21 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC6
Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343)
CVE-2023-2834321 Mar 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
GitHub PoC
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
CVE-2022-36193CRITICAL21 Mar 2023
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang
48RISK
open
VulnCheck XDB
client-side
CVE-2023-23397CRITICALunder attack21 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-30632HIGHunder attack21 Mar 2023
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISK
open
GitHub PoC
Mustafa1986/CVE-2022-22963
CVE-2022-22963CRITICALunder attack21 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC
maldev866/ChExp_CVE-2021-30632
CVE-2021-30632HIGHunder attack21 Mar 2023
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap c
83RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH21 Mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack21 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-24716HIGH20 Mar 2023
Path traversal in Icinga Web 2
78RISK
open
VulnCheck XDB
info-leak
CVE-2022-24716HIGH20 Mar 2023
Path traversal in Icinga Web 2
78RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack20 Mar 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC1
Repo for CVE-2022-46169
CVE-2022-46169CRITICALunder attack20 Mar 2023
Unauthenticated Command Injection
100RISK
open
Metasploit300
MinIO Bootstrap Verify Information Disclosure
CVE-2023-28432HIGHunder attack20 Mar 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10
CVE-2022-24716HIGH20 Mar 2023
Path traversal in Icinga Web 2
78RISK
open
GitHub PoC130
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.
CVE-2023-23397CRITICALunder attack20 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
Patch for MS Outlook Critical Vulnerability - CVSS 9.8
CVE-2023-23397CRITICALunder attack20 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2023-23397CRITICALunder attack20 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
this web is vulnerable against CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware20 Mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Custom exploit written for enumerating usernames as per CVE-2016-6210
CVE-2016-6210MEDIUM19 Mar 2023
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISK
open
VulnCheck XDB
local
CVE-2023-22809HIGH19 Mar 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
infoleak
CVE-2022-24716HIGH19 Mar 2023
Path traversal in Icinga Web 2
78RISK
open
VulnCheck XDB
client-side
CVE-2023-23397CRITICALunder attack19 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook
CVE-2023-23397CRITICALunder attack19 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC9
djackreuter/CVE-2023-23397-PoC
CVE-2023-23397CRITICALunder attack18 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
This script exploits a vulnerability (CVE-2021-25094) in the TypeHub WordPress plugin.
CVE-2021-2509418 Mar 2023
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
GitHub PoC1
CVE-2023-23397 C# PoC
CVE-2023-23397CRITICALunder attack18 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
previouspage 518 / 2,585next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.