Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,866 exploits
GitHub PoC25
PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)
CVE-2021-3560HIGHunder attack30 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC1
CVE-2021-44228 Log4j Summary
CVE-2021-44228CRITICALunder attackransomware30 Apr 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack30 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware29 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
local
CVE-2018-20250HIGHunder attackransomware29 Apr 2022
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack29 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC
Enokiy/spring-RCE-CVE-2022-22965
CVE-2022-22965CRITICALunder attack29 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC8
This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.
CVE-2018-1942229 Apr 2022
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISK
open
GitHub PoC116
PolicyKit CVE-2021-3560 Exploit (Authentication Agent)
CVE-2021-3560HIGHunder attack29 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC2
CVE-2022-29464 POC exploit
CVE-2022-29464CRITICALunder attackransomware29 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC13
A tool for extracting, modifying, and crafting ASDM binary packages (CVE-2022-20829)
CVE-2022-20829CRITICAL28 Apr 2022
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
48RISK
open
GitHub PoC
RedLeavesChilde/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware28 Apr 2022
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
for kernel 3.18.x
CVE-2019-2215HIGHunder attack28 Apr 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
Metasploit600
Zyxel Firewall ZTP Unauthenticated Command Injection
CVE-2022-30525CRITICALunder attack28 Apr 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack28 Apr 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC4
khidottrivi/CVE-2022-22965
CVE-2022-22965CRITICALunder attack27 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC14
CVE-2021-41773&CVE-2021-42013图形化漏洞检测利用工具
CVE-2021-41773HIGHunder attackransomware27 Apr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit600
ZoneMinder Language Settings Remote Code Execution
CVE-2022-2980627 Apr 2022
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an
30RISK
open
GitHub PoC
OS X 10.11.6 LPE PoC for CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMunder attack27 Apr 2022
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISK
open
GitHub PoC
CVE-2022-23046 phpIPAM 1.4.4
CVE-2022-2304626 Apr 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open
VulnCheck XDB
local
CVE-2018-19321HIGHunder attackransomware26 Apr 2022
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RISK
open
GitHub PoC1
CVE-2021-43857(gerapy命令执行)
CVE-2021-43857CRITICAL26 Apr 2022
Gerapy may contain remote code execution vulnerability
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-3180526 Apr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISK
open
Exploit-DB
GitLab 14.9 - Stored Cross-Site Scripting (XSS)
CVE-2022-1175HIGHwebappsruby26 Apr 2022
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RISK
open
GitHub PoC1
Exploit for CVE-2021-3036, HTTP Smuggling + buffer overflow in PanOS 8.x
CVE-2021-3064CRITICAL26 Apr 2022
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
53RISK
open
GitHub PoC210
CVE-2022-22947 注入Godzilla内存马
CVE-2022-22947CRITICALunder attack26 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack26 Apr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
lowkey0808/cve-2022-29464
CVE-2022-29464CRITICALunder attackransomware26 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC
PoC for Dirty COW (CVE-2016-5195)
CVE-2016-5195HIGHunder attack26 Apr 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC8
Page Table Manipulation -- CVE-2018-19321
CVE-2018-19321HIGHunder attackransomware26 Apr 2022
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RISK
open
previouspage 586 / 2,596next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.