Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,323VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
77,866 exploits
GitHub PoC★ 25
PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗GitHub PoC★ 1
CVE-2021-44228 Log4j Summary
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗VulnCheck XDB
local
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗VulnCheck XDB
initial-access
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open ↗VulnCheck XDB
local
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open ↗VulnCheck XDB
local
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗GitHub PoC
Enokiy/spring-RCE-CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC★ 8
This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISK
open ↗GitHub PoC★ 116
PolicyKit CVE-2021-3560 Exploit (Authentication Agent)
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗GitHub PoC★ 2
CVE-2022-29464 POC exploit
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open ↗GitHub PoC★ 13
A tool for extracting, modifying, and crafting ASDM binary packages (CVE-2022-20829)
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
48RISK
open ↗GitHub PoC
RedLeavesChilde/CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 3
for kernel 3.18.x
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open ↗Metasploit600
Zyxel Firewall ZTP Unauthenticated Command Injection
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open ↗GitHub PoC★ 4
khidottrivi/CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC★ 14
CVE-2021-41773&CVE-2021-42013图形化漏洞检测利用工具
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Metasploit600
ZoneMinder Language Settings Remote Code Execution
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an
30RISK
open ↗GitHub PoC
OS X 10.11.6 LPE PoC for CVE-2016-4655 / CVE-2016-4656
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISK
open ↗GitHub PoC
CVE-2022-23046 phpIPAM 1.4.4
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open ↗VulnCheck XDB
local
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RISK
open ↗GitHub PoC★ 1
CVE-2021-43857(gerapy命令执行)
Gerapy may contain remote code execution vulnerability
60RISK
open ↗VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISK
open ↗Exploit-DB
GitLab 14.9 - Stored Cross-Site Scripting (XSS)
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RISK
open ↗GitHub PoC★ 1
Exploit for CVE-2021-3036, HTTP Smuggling + buffer overflow in PanOS 8.x
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
53RISK
open ↗GitHub PoC★ 210
CVE-2022-22947 注入Godzilla内存马
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open ↗VulnCheck XDB
initial-access
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open ↗GitHub PoC
lowkey0808/cve-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open ↗GitHub PoC
PoC for Dirty COW (CVE-2016-5195)
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC★ 8
Page Table Manipulation -- CVE-2018-19321
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.