Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,772 exploits
GitHub PoC1
michealadams30/Cve-2022-30190
CVE-2022-30190HIGHunder attackransomware26 Dec 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2022-3699HIGH25 Dec 2022
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RISK
open
GitHub PoC
CVE-2022-26134 GO POC 练习
CVE-2022-26134CRITICALunder attackransomware25 Dec 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware25 Dec 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack25 Dec 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
hycheng15/CVE-2021-3156
CVE-2021-3156HIGHunder attack25 Dec 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
G01d3nW01f/CVE-2021-29447
CVE-2021-29447HIGH25 Dec 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC7
-- FOR EDUCATIONAL USE ONLY -- Proof-of-Concept RCE for CVE-2022-1388, plus some added functionality for blue and red teams
CVE-2022-1388CRITICALunder attackransomware24 Dec 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware24 Dec 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-41080HIGHunder attackransomware23 Dec 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
local
CVE-2022-46689HIGH23 Dec 2022
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RISK
open
GitHub PoC1
ohnonoyesyes/CVE-2022-41080
CVE-2022-41080HIGHunder attackransomware23 Dec 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC26
Exploits GitLab authenticated RCE vulnerability known as CVE-2022-2884.
CVE-2022-2884CRITICAL22 Dec 2022
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RISK
open
GitHub PoC14
CVE-2021-42287/CVE-2021-42278 Exploiter
CVE-2021-42287HIGHunder attackransomware22 Dec 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-41082HIGHunder attackransomware22 Dec 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC93
PoC for the CVE-2022-41080 , CVE-2022-41082 and CVE-2022-41076 Vulnerabilities Affecting Microsoft Exchange Servers
CVE-2022-41082HIGHunder attackransomware22 Dec 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-41080HIGHunder attackransomware22 Dec 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC
CVE-2022-0847
CVE-2022-0847HIGHunder attack21 Dec 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC2
devengpk/CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware21 Dec 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
this exemple of application permet to test the vunerability CVE_2017-5638
CVE-2017-5638CRITICALunder attackransomware21 Dec 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware21 Dec 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack21 Dec 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALunder attackransomware20 Dec 2022
Unauthenticated remote code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-47986CRITICALunder attackransomware20 Dec 2022
IBM Aspera Faspex code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4966CRITICALunder attackransomware20 Dec 2022
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-24086CRITICALunder attack20 Dec 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
GitHub PoC6
Proof of concept of CVE-2022-24086
CVE-2022-24086CRITICALunder attack20 Dec 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
GitHub PoC
devengpk/CVE-2022-36804
CVE-2022-36804HIGHunder attack20 Dec 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC4
🐍 Python Exploit for CVE-2021-45010
CVE-2021-4501020 Dec 2022
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RISK
open
GitHub PoC1
devengpk/CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware18 Dec 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
previouspage 537 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.