Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
CVE-2023-0913MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System sql injection
33RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - Broken Authentication
CVE-2023-0905HIGHwebappsphp06 Apr 2023
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RISK
open
Exploit-DBVexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
CVE-2023-0916MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System Users.php access control
33RISK
open
Exploit-DBVexDay Proof
Auto Dealer Management System v1.0 - SQL Injection
CVE-2023-0912MEDIUMwebappsphp06 Apr 2023
SourceCodester Auto Dealer Management System sql injection
33RISK
open
Exploit-DBVexDay Proof
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
CVE-2022-40032CRITICALwebappsphp06 Apr 2023
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet
68RISK
open
Exploit-DBVexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
CVE-2023-0943MEDIUMwebappsphp06 Apr 2023
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
CVE-2023-0904MEDIUMwebappsphp06 Apr 2023
SourceCodester Employee Task Management System task-details.php sql injection
33RISK
open
Exploit-DBVexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
CVE-2023-0902LOWwebappsphp06 Apr 2023
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISK
open
Exploit-DBVexDay Proof
BTCPay Server v1.7.4 - HTML Injection
CVE-2023-0493MEDIUMwebappsmultiple05 Apr 2023
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RISK
open
Exploit-DBVexDay Proof
Answerdev 1.0.3 - Account Takeover
CVE-2023-0744CRITICALwebappsgo05 Apr 2023
Improper Access Control in answerdev/answer
48RISK
open
Exploit-DBVexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
CVE-2022-46604HIGHwebappsphp05 Apr 2023
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISK
open
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
CVE-2022-31125CRITICALwebappspython03 Apr 2023
Authentication Bypass in Roxy-wi
53RISK
open
Exploit-DBVexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
CVE-2020-25213CRITICALunder attackwebappsphp03 Apr 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
CVE-2023-23161webappsphp03 Apr 2023
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RISK
open
Exploit-DBVexDay Proof
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
CVE-2023-23488CRITICALwebappsphp03 Apr 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISK
open
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
CVE-2022-31126CRITICALwebappspython03 Apr 2023
Unauthenticated Remote Code Execution in Roxy-wi
75RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
CVE-2023-23163webappsphp03 Apr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
23RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
CVE-2023-23162webappsphp03 Apr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RISK
open
Exploit-DBVexDay Proof
Apache 2.4.x - Buffer Overflow
CVE-2021-44790webappsmultiple01 Apr 2023
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISK
open
Exploit-DBVexDay Proof
GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-2884CRITICALwebappsruby01 Apr 2023
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RISK
open
Exploit-DBVexDay Proof
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
CVE-2022-48197webappsphp01 Apr 2023
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RISK
open
Exploit-DBVexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-1565HIGHwebappsphp29 Mar 2023
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RISK
open
Exploit-DBVexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGHwebappsphp28 Mar 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39291MEDIUMwebappsphp27 Mar 2023
Denial of service through logs in zoneminder
33RISK
open
Exploit-DBVexDay Proof
Grafana <=6.2.4 - HTML Injection
CVE-2019-13068webappstypescript27 Mar 2023
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39290HIGHwebappsphp27 Mar 2023
CSRF key bypass using HTTP methods in zoneminder
41RISK
open
Exploit-DBVexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CVE-2022-39285HIGHwebappsphp27 Mar 2023
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RISK
open
Exploit-DBVexDay Proof
NEX-Forms WordPress plugin < 7.9.7 - Authenticated SQLi
CVE-2022-3142webappsphp25 Mar 2023
NEX-Forms < 7.9.7 - Authenticated SQLi
43RISK
open
Exploit-DBVexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
CVE-2022-35155MEDIUMwebappsphp25 Mar 2023
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RISK
open
Exploit-DBVexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
CVE-2022-26149webappsphp25 Mar 2023
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.