Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,008cataloged exploits
35,919CVEs with public exploitation
24,695lab-tested
77,813 exploits
GitHub PoC
CVE-2014-1767在win7_x64平台的EXP和分析文章
CVE-2014-176712 Feb 2022
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack10 Feb 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC
docker lab setup for kibana-7609
CVE-2019-7609CRITICALunder attack10 Feb 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC
puckiestyle/CVE-2022-20699
CVE-2022-20699CRITICALunder attack10 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
Exploit-DB
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
CVE-2021-24931webappsphp10 Feb 2022
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALunder attack10 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
GitHub PoC2
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows a Local Or Remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.
CVE-2022-2508910 Feb 2022
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RISK
open
Exploit-DB
Hospital Management Startup 1.0 - 'Multiple' SQLi
CVE-2022-23366webappsphp10 Feb 2022
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
23RISK
open
Metasploit300
Strapi CMS Unauthenticated Password Reset
CVE-2019-1881809 Feb 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
Exploit-DB
AtomCMS v2.0 - SQLi
CVE-2022-24223webappsphp09 Feb 2022
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
50RISK
open
Exploit-DB
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
CVE-2021-24901webappsphp08 Feb 2022
Security Audit <= 1.0.0 - Admin+ Stored Cross Site Scripting
23RISK
open
Exploit-DB
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
CVE-2022-0448webappsphp08 Feb 2022
CP Blocks < 1.0.15 - Admin+ Stored Cross-Site Scripting
23RISK
open
Exploit-DB
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
CVE-2021-46398webappsmultiple08 Feb 2022
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RISK
open
Exploit-DB
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
CVE-2020-35749webappsphp08 Feb 2022
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RISK
open
GitHub PoC795
Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)
CVE-2022-21999HIGHunder attackransomware08 Feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
98RISK
open
Exploit-DB
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
CVE-2019-18818webappsnodejs08 Feb 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware08 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
CVE-2012-1876 win7_x86和x64平台分析,EXP、POC代码和分析文档
CVE-2012-187608 Feb 2022
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RISK
open
Exploit-DB
Hospital Management System 4.0 - 'multiple' SQL Injection
CVE-2022-24263webappsphp08 Feb 2022
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
23RISK
open
VulnCheck XDB
local
CVE-2022-21999HIGHunder attackransomware08 Feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
98RISK
open
Metasploit300
CVE-2022-21999 SpoolFool Privesc
CVE-2022-21999HIGHunder attackransomware08 Feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
98RISK
open
Metasploit200
Netfilter nft_set_elem_init Heap Overflow Privilege Escalation
CVE-2022-3491807 Feb 2022
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buff
38RISK
open
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALunder attack07 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
VulnCheck XDB
local
CVE-2022-21882HIGHunder attackransomware07 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC2
Worm written in python, abuses CVE-2020-7247
CVE-2020-7247CRITICALunder attack07 Feb 2022
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC10
kernel exploit
CVE-2015-132807 Feb 2022
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
VulnCheck XDB
local
CVE-2015-132807 Feb 2022
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC49
lpe poc for cve-2022-21882
CVE-2022-21882HIGHunder attackransomware07 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC237
Cisco Anyconnect VPN unauth RCE (rwx stack)
CVE-2022-20699CRITICALunder attack07 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
GitHub PoC6
Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit
CVE-2020-3574906 Feb 2022
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RISK
open
previouspage 608 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.