Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
8,195 exploits
VulnCheck XDB
client-side
CVE-2023-2812112 Jul 2023
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISK
open
VulnCheck XDB
client-side
CVE-2023-27372CRITICAL11 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM11 Jul 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware11 Jul 2023
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2023-346011 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
infoleak
CVE-2022-45354MEDIUM11 Jul 2023
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack10 Jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2023-22809HIGH10 Jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack10 Jul 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack09 Jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
client-side
CVE-2023-346009 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
infoleak
CVE-2023-35843HIGH09 Jul 2023
NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access
56RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-3496009 Jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-34362CRITICALunder attackransomware09 Jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
VulnCheck XDB
client-side
CVE-2023-2982CRITICAL07 Jul 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISK
open
VulnCheck XDB
client-side
CVE-2023-346007 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack07 Jul 2023
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack06 Jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM06 Jul 2023
Cross site scripting
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALunder attack05 Jul 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-346005 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL05 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM04 Jul 2023
Cross site scripting
70RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack04 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-2834303 Jul 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL03 Jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-3496003 Jul 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALunder attackransomware03 Jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-3710CRITICAL03 Jul 2023
Printer web page invalid command execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack02 Jul 2023
Openfire administration console authentication bypass
100RISK
open
previouspage 158 / 274next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.