Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
8,195 exploits
VulnCheck XDB
local
CVE-2020-0041HIGHunder attack14 Aug 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware14 Aug 2023
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM13 Aug 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack13 Aug 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-34621CRITICAL12 Aug 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALunder attack11 Aug 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Aug 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
client-side
CVE-2021-2503209 Aug 2023
PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
38RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864609 Aug 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864609 Aug 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-34621CRITICAL09 Aug 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM09 Aug 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-4542MEDIUM09 Aug 2023
D-Link DAR-8000-10 sys1.php os command injection
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-38408CRITICAL09 Aug 2023
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
VulnCheck XDB
client-side
CVE-2022-095207 Aug 2023
Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
43RISK
open
VulnCheck XDB
initial-access
CVE-2023-26067HIGH07 Aug 2023
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALunder attackransomware06 Aug 2023
Unauthenticated remote code execution
100RISK
open
VulnCheck XDB
local
CVE-2023-22809HIGH06 Aug 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware06 Aug 2023
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
local
CVE-2021-22555HIGHunder attack05 Aug 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-2732CRITICAL05 Aug 2023
MStore API <= 3.9.2 - Authentication Bypass
75RISK
open
VulnCheck XDB
infoleak
CVE-2013-382705 Aug 2023
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RISK
open
VulnCheck XDB
initial-access
CVE-2018-6789CRITICALunder attackransomware05 Aug 2023
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
VulnCheck XDB
client-side
CVE-2019-1135805 Aug 2023
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
VulnCheck XDB
client-side
CVE-2023-27163MEDIUM05 Aug 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-3519CRITICALunder attackransomware05 Aug 2023
Unauthenticated remote code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-35082CRITICALunder attackransomware04 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864603 Aug 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864602 Aug 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware02 Aug 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
previouspage 155 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.