Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
77,813 exploits
Metasploit600
Local Privilege Escalation in polkits pkexec
CVE-2021-4034HIGHunder attackransomware25 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-21371HIGH25 Jan 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware25 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware25 Jan 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC46
numanturle/CVE-2022-0332
CVE-2022-033225 Jan 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RISK
open
GitHub PoC27
Oracle WebLogic Server 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 Local File Inclusion
CVE-2022-21371HIGH25 Jan 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
VulnCheck XDB
client-side
CVE-2019-573625 Jan 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
info-leak
CVE-2021-39312HIGH24 Jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISK
open
GitHub PoC
Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read
CVE-2021-39312HIGH24 Jan 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISK
open
GitHub PoC2
Strapi CMS 3.0.0-beta.17.4 - Unauthenticated Remote Code Execution (CVE-2019-18818, CVE-2019-19609)
CVE-2019-1960923 Jan 2022
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC28
CVE-2022-21907 Vulnerability PoC
CVE-2022-21907CRITICAL23 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL23 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-1881823 Jan 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
Metasploit300
Wordpress RegistrationMagic task_ids Authenticated SQLi
CVE-2021-2486223 Jan 2022
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RISK
open
GitHub PoC1
jcarabantes/CVE-2022-23046
CVE-2022-2304622 Jan 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open
GitHub PoC5
test 反向辣鸡数据投放 CVE-2022-23305 工具 利用 教程 Exploit POC
CVE-2022-23305CRITICAL21 Jan 2022
SQL injection in JDBC Appender in Apache Log4j V1
60RISK
open
Metasploit600
Apache Couchdb Erlang RCE
CVE-2022-24706CRITICALunder attack21 Jan 2022
Remote Code Execution Vulnerability in Packaging
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-24489CRITICALunder attack20 Jan 2022
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISK
open
GitHub PoC375
CVE-2022-0185
CVE-2022-0185HIGHunder attack19 Jan 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack19 Jan 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
local
CVE-2022-0185HIGHunder attack19 Jan 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
GitHub PoC24
💀 Linux local root exploit for CVE-2018-18955
CVE-2018-1895519 Jan 2022
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open
Metasploit600
Oracle Access Manager unauthenticated Remote Code Execution
CVE-2021-35587CRITICALunder attack19 Jan 2022
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack18 Jan 2022
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-21661HIGH18 Jan 2022
SQL injection in WordPress
78RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack18 Jan 2022
Grafana path traversal
100RISK
open
Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure
CVE-2022-23178webappshardware18 Jan 2022
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RISK
open
VulnCheck XDB
client-side
CVE-2020-1472MEDIUMunder attackransomware18 Jan 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware18 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
KasunPriyashan/Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability
CVE-2016-5195HIGHunder attack17 Jan 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
previouspage 614 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.