Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,893 exploits
VulnCheck XDB
initial-access
CVE-2021-3180526 Apr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware25 Apr 2022
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-32849HIGH25 Apr 2022
Arbitrary command execution in Gerapy
41RISK
open
GitHub PoC
This is the story of CVE-2022-0847, a vulnerability in the Linux kernel since 5.8 which allows overwriting data in arbitrary read-only files. This leads to privilege escalation because unprivileged processes can inject code into root processes.
CVE-2022-0847HIGHunder attack25 Apr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
anldori/CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware25 Apr 2022
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
Metasploit600
Tatsu Wordpress Plugin RCE
CVE-2021-2509425 Apr 2022
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware24 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware24 Apr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2014-0160_Heartbleed
CVE-2014-0160HIGHunder attack24 Apr 2022
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC1
Proof of concept exploit for CVE-2021-42697: Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.
CVE-2021-4269724 Apr 2022
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RISK
open
GitHub PoC
My research about CVE-2021-4034
CVE-2021-4034HIGHunder attackransomware24 Apr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC5
Proof of concept exploit for CVE-2022-29548: A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.
CVE-2022-29548MEDIUM24 Apr 2022
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,
60RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware24 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC28
😭 WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.
CVE-2022-29464CRITICALunder attackransomware24 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC5
mariomamo/CVE-2022-22965
CVE-2022-22965CRITICALunder attack23 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
CVE-2022-26809-RCE
CVE-2022-26809CRITICAL23 Apr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack23 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
client-side
CVE-2017-0199HIGHunder attackransomware22 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
A python script/generator, for generating and exploiting Microsoft vulnerability
CVE-2017-0199HIGHunder attackransomware22 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
This repository contains a PoC for remote code execution CVE-2022-26809
CVE-2022-26809CRITICAL22 Apr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC1
0xAgun/CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC5
cve-2022-29464 批量脚本
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC5
WSO2 RCE (CVE-2022-29464)
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC3
Repository containing nse script for vulnerability CVE-2022-29464 known as WSO2 RCE.
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC2
tufanturhan/wso2-rce-cve-2022-29464
CVE-2022-29464CRITICALunder attackransomware21 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC2
Pre-auth RCE bug CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware21 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC1
c4mx/CVE-2022-22965_PoC
CVE-2022-22965CRITICALunder attack21 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-1092421 Apr 2022
The ebook-download plugin before 1.2 for WordPress has directory traversal.
38RISK
open
GitHub PoC1
Phantomlancer123/CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware20 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
previouspage 587 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.