Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,772 exploits
GitHub PoC2
Validation of Arbitrary File Read Vulnerabilities in Dell OpenManage Server Administrator (OMSA) - CVE-2016-4004, CVE-2021-21514 and CVE-2020-5377.
CVE-2016-400430 Nov 2022
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RISK
open
GitHub PoC2
Validation of Arbitrary File Read Vulnerabilities in Dell OpenManage Server Administrator (OMSA) - CVE-2016-4004, CVE-2021-21514 and CVE-2020-5377.
CVE-2020-5377CRITICAL30 Nov 2022
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISK
open
GitHub PoC3
revanmalang/CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware30 Nov 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware30 Nov 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
fei9747/CVE-2021-4034
CVE-2021-4034HIGHunder attackransomware29 Nov 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
fei9747/CVE-2017-16995
CVE-2017-1699529 Nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware29 Nov 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack29 Nov 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack29 Nov 2022
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
client-side
CVE-2022-41412HIGH29 Nov 2022
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and exec
56RISK
open
GitHub PoC
fei9747/CVE-2016-5195
CVE-2016-5195HIGHunder attack29 Nov 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC1
fei9747/CVE-2021-3493
CVE-2021-3493HIGHunder attack29 Nov 2022
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC100
clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability CVE-2021-3156 and the fact that for some reasons, Google's afl-fuzz doesn't allow for unlimited argument or option specification.
CVE-2021-3156HIGHunder attack28 Nov 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack28 Nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
CVE-2022-22965 proof of concept
CVE-2022-22965CRITICALunder attack28 Nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-3355828 Nov 2022
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, previe
43RISK
open
GitHub PoC
ClemExp/CVE-2022-22965-PoC
CVE-2022-22965CRITICALunder attack28 Nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
CVE-2017-9833 POC
CVE-2017-983325 Nov 2022
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read
50RISK
open
VulnCheck XDB
infoleak
CVE-2017-983325 Nov 2022
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read
50RISK
open
VulnCheck XDB
client-side
CVE-2022-39197MEDIUMunder attack24 Nov 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
GitHub PoC2
CVE-2022-39197
CVE-2022-39197MEDIUMunder attack24 Nov 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
GitHub PoC14
Apache HTTP-Server 2.4.49-2.4.50 Path Traversal & Remote Code Execution PoC (CVE-2021-41773 & CVE-2021-42013)
CVE-2021-41773HIGHunder attackransomware22 Nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC8
PoC for CVE-2021-31166 and CVE-2022-21907
CVE-2022-21907CRITICAL22 Nov 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC7
grails/GSSC-CVE-2022-41923
CVE-2022-41923CRITICAL22 Nov 2022
Grails Spring Security Core plugin vulnerable to privilege escalation
48RISK
open
Metasploit600
VSCode ipynb Remote Development RCE
CVE-2022-41034HIGH22 Nov 2022
Visual Studio Code Remote Code Execution Vulnerability
48RISK
open
Metasploit0
WhatsUp Gold Credentials Dump
CVE-2022-2984722 Nov 2022
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to i
30RISK
open
Metasploit0
WhatsUp Gold Credentials Dump
CVE-2022-2984822 Nov 2022
In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke
18RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack22 Nov 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL22 Nov 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
dr4g0n23/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware22 Nov 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
previouspage 540 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.