Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,724 exploits
GitHub PoC2
CVE-2022-47986: Python, Ruby, NMAP and Metasploit modules to exploit the vulnerability.
CVE-2022-47986CRITICALunder attackransomware09 Mar 2023
IBM Aspera Faspex code execution
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-35391CRITICAL09 Mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open
GitHub PoC4
SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.
CVE-2018-15473MEDIUM09 Mar 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC7
Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload
CVE-2022-4395CRITICAL09 Mar 2023
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RISK
open
GitHub PoC2
开源,go多并发批量探测poc,准确率高
CVE-2023-23752MEDIUMunder attack09 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC2
CVE-2019-15107 图形化测试程序
CVE-2019-15107CRITICALunder attackransomware09 Mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC7
Bulk scanner + get config from CVE-2023-23752
CVE-2023-23752MEDIUMunder attack09 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware09 Mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
sei-fish/CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware09 Mar 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC4
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHunder attackransomware09 Mar 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
Tenda f3 Malformed HTTP Request Header Processing Vulnerability.
CVE-2020-35391CRITICAL09 Mar 2023
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open
GitHub PoC59
A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF document. The attacker could deliver this file as an email attachment (or other means).
CVE-2023-21716CRITICAL08 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar
CVE-2023-21716CRITICAL08 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
local
CVE-2023-21716CRITICAL08 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
client-side
CVE-2021-21224HIGHunder attack08 Mar 2023
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a
83RISK
open
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL08 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL07 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
client-side
CVE-2020-1604007 Mar 2023
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack07 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL07 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH07 Mar 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack07 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC46
RTF Crash POC Python 3.11 Windows 10
CVE-2023-21716CRITICAL07 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
adriyansyah-mf/CVE-2023-23752
CVE-2023-23752MEDIUMunder attack07 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC4
FeatherStark/CVE-2023-21716
CVE-2023-21716CRITICAL07 Mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
Metasploit300
Pretalx Arbitrary File Read/Limited File Write
CVE-2023-28458MEDIUM07 Mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RISK
open
GitHub PoC
Script in Ruby for the CVE-2022-35914 - RCE in GLPI
CVE-2022-35914CRITICALunder attack07 Mar 2023
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
Metasploit600
Pretalx Limited File Write to Remote Code Execution
CVE-2023-28458MEDIUM07 Mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
28RISK
open
GitHub PoC8
spring cloud function 一键利用工具! by charis 博客https://charis3306.top/
CVE-2022-22963CRITICALunder attack07 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Metasploit300
Pretalx Arbitrary File Read/Limited File Write
CVE-2023-28459MEDIUM07 Mar 2023
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload craft
28RISK
open
previouspage 524 / 2,591next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.