Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,765cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,724 exploits
VulnCheck XDB
infoleak
CVE-2023-23397CRITICALunder attack17 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
CVE-2023-23397 Remediation Script (Powershell)
CVE-2023-23397CRITICALunder attack17 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2016-1531
CVE-2016-153117 Mar 2023
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISK
open
GitHub PoC7
Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.
CVE-2023-23397CRITICALunder attack17 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC6
Exploit POC for CVE-2023-23397
CVE-2023-23397CRITICALunder attack17 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
j0eyv/CVE-2023-23397
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC39
Simple PoC in PowerShell for CVE-2023-23397
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC4
Python script to create a message with the vulenrability properties set
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC346
api0cradle/CVE-2023-23397-POC-Powershell
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC3
CVE-2023-23397 - Microsoft Outlook Vulnerability
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC7
FortiOS buffer overflow vulnerability
CVE-2022-42475CRITICALunder attackransomware16 Mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Automate JWT Exploit (CVE-2018-0114)
CVE-2018-011416 Mar 2023
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
VulnCheck XDB
initial-access
CVE-2022-42475CRITICALunder attackransomware16 Mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-30136CRITICAL15 Mar 2023
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-1026HIGH15 Mar 2023
Kyocera Net View Address Book Exposure
61RISK
open
VulnCheck XDB
infoleak
CVE-2023-23397CRITICALunder attack15 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC15
Windows Network File System Remote exploit for CVE-2022-30136
CVE-2022-30136CRITICAL15 Mar 2023
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
Proof of concept exploit code for CVE-2020-7388, an unauthenticated RCE as SYSTEM on Sage X3's AdxDSrv Service
CVE-2020-7388CRITICAL15 Mar 2023
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
75RISK
open
GitHub PoC159
Exploit for the CVE-2023-23397
CVE-2023-23397CRITICALunder attack15 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288914 Mar 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
infoleak
CVE-2020-3187CRITICAL14 Mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
GitHub PoC3
An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft
CVE-2021-44228CRITICALunder attackransomware14 Mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Implementation of FOLLINA-CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware14 Mar 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Batch scanning site.
CVE-2020-3187CRITICAL14 Mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
VulnCheck XDB
local
CVE-2022-30190HIGHunder attackransomware14 Mar 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Adobe ColdFusion Unauthenticated Remote Code Execution
CVE-2023-26360HIGHunder attack14 Mar 2023
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
previouspage 522 / 2,591next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.