Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
8,182 exploits
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware27 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALunder attackransomware27 Oct 2023
Unauthenticated remote code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware27 Oct 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALunder attackransomware27 Oct 2023
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack26 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack26 Oct 2023
Grafana path traversal
100RISK
open
VulnCheck XDB
local
CVE-2023-46604CRITICALunder attackransomware26 Oct 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23397CRITICALunder attack26 Oct 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864626 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-536026 Oct 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864625 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
local
CVE-2023-4911HIGHunder attack25 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack25 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack25 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4966CRITICALunder attackransomware25 Oct 2023
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALunder attack25 Oct 2023
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALunder attackransomware25 Oct 2023
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALunder attackransomware25 Oct 2023
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALunder attackransomware25 Oct 2023
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware24 Oct 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALunder attackransomware24 Oct 2023
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware24 Oct 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALunder attack24 Oct 2023
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack23 Oct 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864623 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
local
CVE-2023-36802HIGHunder attack23 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack23 Oct 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
infoleak
CVE-2013-478623 Oct 2023
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack22 Oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware22 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
previouspage 146 / 273next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.