Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,813 exploits
Exploit-DB
Blink1Control2 2.2.7 - Weak Password Encryption
CVE-2022-35513localmultiple20 Sep 2022
The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.
23RISK
open
VulnCheck XDB
initial-access
CVE-2022-36804HIGHunder attack19 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
VulnCheck XDB
local
CVE-2017-12149CRITICALunder attackransomware19 Sep 2022
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC18
Multithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1
CVE-2022-36804HIGHunder attack19 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL18 Sep 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC4
CVE-2022-31814 Exploitation Toolkit.
CVE-2022-31814CRITICAL18 Sep 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC2
All Credit to MaherAzzouzi (https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit). This is a copy of the exploit for CTFs
CVE-2022-37706HIGH18 Sep 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open
GitHub PoC4
CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.
CVE-2019-0708CRITICALunder attackransomware17 Sep 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware17 Sep 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC1
touchmycrazyredhat/CVE-2022-27925-Revshell
CVE-2022-27925HIGHunder attackransomware17 Sep 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC1
pswalia2u/CVE-2020-7246
CVE-2020-724616 Sep 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
GitHub PoC
cve-2010-2553复现
CVE-2010-255316 Sep 2022
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2022-37204 POC
CVE-2022-37204CRITICAL15 Sep 2022
Final CMS 5.1.0 is vulnerable to SQL Injection.
48RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
client-side
CVE-2022-30190HIGHunder attackransomware15 Sep 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
kernel-cyber/CVE-2009-4623
CVE-2009-462315 Sep 2022
Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbi
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
mightysai1997/cve-2021-41773-v-
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
mightysai1997/cve-2021-42013L
CVE-2021-42013CRITICALunder attackransomware15 Sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
mightysai1997/CVE-2021-41773-i-
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
mightysai1997/cve-2021-42013.get
CVE-2021-42013CRITICALunder attackransomware15 Sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
mightysai1997/CVE-2021-41773-L-
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
mightysai1997/CVE-2021-41773-PoC
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
mightysai1997/CVE-2021-41773S
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
mightysai1997/CVE-2021-41773m
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 556 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.