Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,772 exploits
VulnCheck XDB
initial-access
CVE-2022-36804HIGHunder attack23 Jan 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC7
The manage engine mass loader for CVE-2022-47966
CVE-2022-47966CRITICALunder attackransomware23 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
GitHub PoC2
Run on your ManageEngine server
CVE-2022-47966CRITICALunder attackransomware23 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
GitHub PoC28
Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.
CVE-2022-47966CRITICALunder attackransomware23 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALunder attack22 Jan 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC6
Python exploit for RCE in Wordpress
CVE-2020-25213CRITICALunder attack22 Jan 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC165
A script to automate privilege escalation with CVE-2023-22809 vulnerability
CVE-2023-22809HIGH21 Jan 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC1
Demo webapp vulnerable to CVE-2022-44900
CVE-2022-44900CRITICAL21 Jan 2023
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea
48RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-9978MEDIUMunder attack20 Jan 2023
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC4
Remote Code Execution in Social Warfare Plugin before 3.5.3 for Wordpress.
CVE-2019-9978MEDIUMunder attack20 Jan 2023
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC
PoC for cve-2022-47966
CVE-2022-47966CRITICALunder attackransomware19 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALunder attackransomware19 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-42864HIGH19 Jan 2023
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, ma
41RISK
open
Metasploit600
Sudoedit Extra Arguments Priv Esc
CVE-2023-22809HIGH18 Jan 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC
notareaperbutDR34P3r/CVE-2022-40684-Rust
CVE-2022-40684CRITICALunder attackransomware17 Jan 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC1
test for the ioc described for FG-IR-22-398
CVE-2022-42475CRITICALunder attackransomware17 Jan 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
GitHub PoC
Project for the Cyberspace Security class.
CVE-2017-891717 Jan 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALunder attackransomware17 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
GitHub PoC129
POC for CVE-2022-47966 affecting multiple ManageEngine products
CVE-2022-47966CRITICALunder attackransomware17 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
Metasploit600
Oracle Weblogic PreAuth Remote Command Execution via ForeignOpaqueReference IIOP Deserialization
CVE-2023-21839HIGHunder attack17 Jan 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC2
A POC on how to exploit CVE-2022-27518
CVE-2022-27518CRITICALunder attack17 Jan 2023
Unauthenticated remote arbitrary code execution
78RISK
open
GitHub PoC2
CVE-2014-5460
CVE-2014-546017 Jan 2023
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALunder attackransomware17 Jan 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack16 Jan 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC3
RCE POC for CVE-2022-46169
CVE-2022-46169CRITICALunder attack16 Jan 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Exploit For OverlayFS
CVE-2021-3493HIGHunder attack16 Jan 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
nhamle2/CVE-2015-8660
CVE-2015-866015 Jan 2023
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISK
open
GitHub PoC2
Cacti: Unauthenticated Remote Code Execution Exploit in Ruby
CVE-2022-46169CRITICALunder attack15 Jan 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack15 Jan 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC3
cbk914/CVE-2022-26134_check
CVE-2022-26134CRITICALunder attackransomware15 Jan 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
previouspage 533 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.