Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,772 exploits
GitHub PoC4
iliass-dahman/CVE-2022-22963-POC
CVE-2022-22963CRITICALunder attack15 Jan 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC
nhamle2/CVE-2015-8660
CVE-2015-866015 Jan 2023
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack15 Jan 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack15 Jan 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-2227414 Jan 2023
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to
35RISK
open
VulnCheck XDB
initial-access
CVE-2022-21661HIGH13 Jan 2023
SQL injection in WordPress
78RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack13 Jan 2023
Unauthenticated Command Injection
100RISK
open
Metasploit600
pyLoad js2py Python Execution
CVE-2023-0297CRITICAL13 Jan 2023
Code Injection in pyload/pyload
85RISK
open
GitHub PoC9
Exploit to CVE-2022-46169 vulnerability
CVE-2022-46169CRITICALunder attack13 Jan 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware13 Jan 2023
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
CVE 2022-45299
CVE-2022-45299CRITICAL13 Jan 2023
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
48RISK
open
GitHub PoC6
Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.
CVE-2022-21661HIGH13 Jan 2023
SQL injection in WordPress
78RISK
open
Metasploit300
Wordpress Paid Membership Pro code Unauthenticated SQLi
CVE-2023-23488CRITICAL12 Jan 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISK
open
VulnCheck XDB
local
CVE-2022-099512 Jan 2023
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This
38RISK
open
GitHub PoC2
cve-2010-1622 Learning Environment
CVE-2010-162211 Jan 2023
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISK
open
Metasploit600
Ancillary Function Driver (AFD) for WinSock Elevation of Privilege
CVE-2023-21768HIGH10 Jan 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
Metasploit600
ManageEngine ServiceDesk Plus Unauthenticated SAML RCE
CVE-2022-47966CRITICALunder attackransomware10 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
Metasploit600
ManageEngine ADSelfService Plus Unauthenticated SAML RCE
CVE-2022-47966CRITICALunder attackransomware10 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
GitHub PoC
CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8
CVE-2021-29447HIGH10 Jan 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC326
Wh04m1001/CVE-2023-21752
CVE-2023-21752HIGH10 Jan 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RISK
open
Metasploit600
ManageEngine Endpoint Central Unauthenticated SAML RCE
CVE-2022-47966CRITICALunder attackransomware10 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-48323CRITICAL10 Jan 2023
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A
75RISK
open
GitHub PoC1
.NET console application that exploits CVE-2018-9995 vulnerability
CVE-2018-999509 Jan 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL09 Jan 2023
Code Injection in pyload/pyload
85RISK
open
VulnCheck XDB
infoleak
CVE-2018-999509 Jan 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC
CVE-2017-16995 Linux POC
CVE-2017-1699509 Jan 2023
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC
G01d3nW01f/CVE-2021-43798
CVE-2021-43798HIGHunder attack09 Jan 2023
Grafana path traversal
100RISK
open
GitHub PoC
CVE-2017-7308 POC
CVE-2017-730809 Jan 2023
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RISK
open
GitHub PoC28
CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad
CVE-2023-0297CRITICAL09 Jan 2023
Code Injection in pyload/pyload
85RISK
open
GitHub PoC
zabbix saml bypass
CVE-2022-23131CRITICALunder attack09 Jan 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
previouspage 534 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.