Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,900 exploits
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
client-side
CVE-2017-0199HIGHunder attackransomware22 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-1092421 Apr 2022
The ebook-download plugin before 1.2 for WordPress has directory traversal.
38RISK
open
GitHub PoC2
Pre-auth RCE bug CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware21 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC2
tufanturhan/wso2-rce-cve-2022-29464
CVE-2022-29464CRITICALunder attackransomware21 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC1
c4mx/CVE-2022-22965_PoC
CVE-2022-22965CRITICALunder attack21 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack20 Apr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware20 Apr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
CVE-2021-4034 PoC
CVE-2021-4034HIGHunder attackransomware20 Apr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC377
WSO2 RCE (CVE-2022-29464) exploit and writeup.
CVE-2022-29464CRITICALunder attackransomware20 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC
MS CVE 2019-0708 Python Exploit
CVE-2019-0708CRITICALunder attackransomware20 Apr 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
CVE-2017-9841批量扫描及利用脚本。PHPUnit是其中的一个基于PHP的测试框架。 PHPUnit 4.8.28之前的版本和5.6.3之前的5.x版本中的Util/PHP/eval-stdin.php文件存在安全漏洞。远程攻击者可通过发送以‘<?php’字符串开头的HTTP POST数据利用该漏洞执行任意PHP代码。
CVE-2017-9841CRITICALunder attack20 Apr 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC1
Phantomlancer123/CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware20 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack20 Apr 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
client-side
CVE-2017-0199HIGHunder attackransomware20 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware20 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
Exploit-DB
Easy Appointments 1.4.2 - Information Disclosure
CVE-2022-0482CRITICALwebappsphp19 Apr 2022
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISK
open
Exploit-DB
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
CVE-2022-24181webappsphp19 Apr 2022
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to
38RISK
open
Exploit-DB
WordPress Plugin Popup Maker 1.16.5 - Stored Cross-Site Scripting (Authenticated)
CVE-2022-1104webappsphp19 Apr 2022
Popup Maker < 1.16.5 - Admin+ Stored Cross-Site Scripting
35RISK
open
Exploit-DB
Zyxel NWA-1100-NH - Command Injection
CVE-2021-4039CRITICALremotehardware19 Apr 2022
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to exec
70RISK
open
Exploit-DB
REDCap 11.3.9 - Stored Cross Site Scripting
CVE-2021-42136webappsphp19 Apr 2022
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows
23RISK
open
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34878MEDIUM19 Apr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contain a SQL injection vulnerability at /vicidial/user_stats.php.
28RISK
open
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34876MEDIUM19 Apr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contain multiple SQL injection vulnerability at /vicidial/admin.php.
28RISK
open
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34877MEDIUM19 Apr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contains a SQL injection vulnerability at /vicidial/AST_agent_time_sheet.php.
28RISK
open
GitHub PoC
ms15-034 or CVE-2015-1635 批量扫描
CVE-2015-1635CRITICALunder attack19 Apr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-20198CRITICALunder attack19 Apr 2022
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALunder attack19 Apr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open
GitHub PoC
CVE-2021-42013 - Apache 2.4.50
CVE-2021-42013CRITICALunder attackransomware18 Apr 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3180518 Apr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISK
open
GitHub PoC
CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware18 Apr 2022
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
previouspage 588 / 2,597next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.