Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,813 exploits
VulnCheck XDB
initial-access
CVE-2022-2297204 Oct 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
50RISK
open
VulnCheck XDB
initial-access
CVE-2022-41082HIGHunder attackransomware04 Oct 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC60
Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.
CVE-2017-9248CRITICALunder attack04 Oct 2022
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9805HIGHunder attack03 Oct 2022
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC49
SecLabResearchBV/CVE-2022-34718-PoC
CVE-2022-34718CRITICAL03 Oct 2022
Windows TCP/IP Remote Code Execution Vulnerability
60RISK
open
GitHub PoC
CentarisCyber/CVE-2022-41040_Mitigation
CVE-2022-41040HIGHunder attackransomware03 Oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2020-28949HIGHunder attack03 Oct 2022
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper
100RISK
open
GitHub PoC3
CVE-2017-9805 POC
CVE-2017-9805HIGHunder attack03 Oct 2022
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC19
CVE-2022-41040 nuclei template
CVE-2022-41040HIGHunder attackransomware02 Oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-41040HIGHunder attackransomware02 Oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
PoC of CVE-2022-24086
CVE-2022-24086CRITICALunder attack01 Oct 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
Metasploit600
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
CVE-2022-21587CRITICALunder attackransomware01 Oct 2022
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open
GitHub PoC
WonderCMS 3.1.3 - Authenticated Remote Code Execution
CVE-2020-3531401 Oct 2022
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al
28RISK
open
VulnCheck XDB
infoleak
CVE-2022-41082HIGHunder attackransomware01 Oct 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware01 Oct 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC18
A loader for zimbra 2022 rce (cve-2022-27925)
CVE-2022-27925HIGHunder attackransomware01 Oct 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC80
Nmap scripts to detect exchange 0-day (CVE-2022-41082) vulnerability
CVE-2022-41082HIGHunder attackransomware01 Oct 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC7
CVE-2020-8813 - RCE through graph_realtime.php in Cacti 1.2.8
CVE-2020-881330 Sep 2022
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open
GitHub PoC
Laravel debug mode - Remote Code Execution (RCE)
CVE-2021-3129CRITICALunder attackransomware30 Sep 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALunder attack30 Sep 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-881330 Sep 2022
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open
GitHub PoC51
cosad3s/CVE-2022-35914-poc
CVE-2022-35914CRITICALunder attack30 Sep 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware30 Sep 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC3
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44077CRITICALunder attack29 Sep 2022
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISK
open
GitHub PoC2
Golang Proof of Concept Exploit for CVE-2021-44077: PreAuth RCE in ManageEngine ServiceDesk Plus < 11306
CVE-2021-44077CRITICALunder attack29 Sep 2022
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISK
open
Metasploit600
Microsoft Exchange ProxyNotShell RCE
CVE-2022-41040HIGHunder attackransomware28 Sep 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
previouspage 553 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.