Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,772 exploits
GitHub PoC2
Exploit updated to use Python 3.
CVE-2020-0688HIGHunder attackransomware19 Oct 2022
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC
onlyHerold22/CVE-2022-27925-PoC
CVE-2022-27925HIGHunder attackransomware19 Oct 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC
neerazz/CVE-2022-42889
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC4
Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).
CVE-2022-40684CRITICALunder attackransomware19 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC
eunomie/cve-2022-42889-check
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC57
Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
infoleak
CVE-2022-40684CRITICALunder attackransomware19 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware19 Oct 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
Metasploit600
SolarWinds Information Service (SWIS) .NET Deserialization From AMQP RCE
CVE-2022-38108HIGH19 Oct 2022
SolarWinds Platform Deserialization of Untrusted Data
48RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288918 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288918 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288918 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC39
cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text version 1.10.
CVE-2022-4288918 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC10
A simple application that shows how to exploit the CVE-2022-42889 vulnerability
CVE-2022-4288918 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
CVE-2014-3704 aka Drupalgeddon - Form-Cache Injection Method
CVE-2014-370418 Oct 2022
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
GitHub PoC1
An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.
CVE-2022-4288918 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC76
Dockerized POC for CVE-2022-42889 Text4Shell
CVE-2022-4288918 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-5418HIGHunder attack17 Oct 2022
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC2
jsongmax/Fortinet-CVE-2022-40684
CVE-2022-40684CRITICALunder attackransomware17 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALunder attackransomware17 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALunder attackransomware17 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288917 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC2
Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图,我们可以通过修改访问某控制器的请求包,通过“…/…/…/…/”来达到路径穿越的目的,然后再通过“{{”来进行模板查询路径的闭合,使得所要访问的文件被当做外部模板来解析。
CVE-2019-5418HIGHunder attack17 Oct 2022
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open
GitHub PoC
puckiestyle/CVE-2022-40684
CVE-2022-40684CRITICALunder attackransomware17 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC34
Proof of Concept for the Apache commons-text vulnerability CVE-2022-42889.
CVE-2022-4288917 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC4
ClusterImagePolicy demo for cve-2022-42889 text4shell
CVE-2022-4288917 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-24990CRITICALunder attackransomware17 Oct 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISK
open
GitHub PoC4
jsongmax/terraMaster-CVE-2022-24990
CVE-2022-24990CRITICALunder attackransomware17 Oct 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RISK
open
previouspage 547 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.