Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,813 exploits
GitHub PoC19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
CVE-2017-1000486CRITICALunder attack09 Sep 2022
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack09 Sep 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALunder attack09 Sep 2022
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open
GitHub PoC
[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing
CVE-2014-6271CRITICALunder attack09 Sep 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.
CVE-2021-44228CRITICALunder attackransomware08 Sep 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC35
A real exploit for BitBucket RCE CVE-2022-36804
CVE-2022-36804HIGHunder attack07 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-36804HIGHunder attack07 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
Metasploit300
Syncovery For Linux Web-GUI Session Token Brute-Forcer
CVE-2022-3653606 Sep 2022
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be
18RISK
open
Metasploit600
Syncovery For Linux Web-GUI Authenticated Remote Command Execution
CVE-2022-3653406 Sep 2022
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote c
30RISK
open
GitHub PoC
Remediation for CVE-2013-3900
CVE-2013-3900MEDIUMunder attack06 Sep 2022
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC23
CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
CVE-2021-34527HIGHunder attackransomware05 Sep 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-34527HIGHunder attackransomware05 Sep 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
Metasploit500
pfSense plugin pfBlockerNG unauthenticated RCE as root
CVE-2022-31814CRITICAL05 Sep 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC1
Redis RCE through Lua Sandbox Escape vulnerability
CVE-2022-0543CRITICALunder attack05 Sep 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
GitHub PoC22
CVE-2022-2586: Linux kernel nft_object UAF
CVE-2022-2586MEDIUMunder attack03 Sep 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISK
open
GitHub PoC1
0xrobiul/CVE-2018-15473
CVE-2018-15473MEDIUM03 Sep 2022
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware03 Sep 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
local
CVE-2022-2586MEDIUMunder attack03 Sep 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISK
open
VulnCheck XDB
local
CVE-2021-31956HIGHunder attack02 Sep 2022
Windows NTFS Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC5
Win10 20H2 LPE for CVE-2021-31956
CVE-2021-31956HIGHunder attack02 Sep 2022
Windows NTFS Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC4
Powertek PDU身份绕过
CVE-2022-33174CRITICAL02 Sep 2022
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RISK
open
GitHub PoC2
Zabbix-SAML-Bypass: CVE-2022-23131
CVE-2022-23131CRITICALunder attack02 Sep 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC
shavchen/CVE-2022-26138
CVE-2022-26138CRITICALunder attack01 Sep 2022
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISK
open
GitHub PoC6
OpenSSL
CVE-2022-1292CRITICAL01 Sep 2022
The c_rehash script allows command injection
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-0543CRITICALunder attack01 Sep 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
GitHub PoC
75ACOL/CVE-2022-22963
CVE-2022-22963CRITICALunder attack01 Sep 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Metasploit600
Symmetricom SyncServer Unauthenticated Remote Command Execution
CVE-2022-40022CRITICAL31 Aug 2022
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
85RISK
open
GitHub PoC
Proof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)
CVE-2022-0847HIGHunder attack31 Aug 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware31 Aug 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack31 Aug 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
previouspage 558 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.