Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
24,460 exploits
Exploit-DB
FLEX 1080 < 1085 Web 1.6.0 - Denial of Service
CVE-2022-2591HIGHdosandroid13 May 2023
TEM FLEX-1085 reboot denial of service
41RISK
open
Exploit-DB
Jedox 2020.2.5 - Disclosure of Database Credentials via Improper Access Controls
CVE-2022-47874MEDIUMwebappsphp05 May 2023
Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat
38RISK
open
Exploit-DBVexDay Proof
Online Pizza Ordering System v1.0 - Unauthenticated File Upload
CVE-2023-2246MEDIUMwebappsphp05 May 2023
SourceCodester Online Pizza Ordering System unrestricted upload
33RISK
open
Exploit-DB
Jedox 2022.4.2 - Disclosure of Database Credentials via Connection Checks
CVE-2022-47880MEDIUMwebappsphp05 May 2023
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users wi
33RISK
open
Exploit-DB
Jedox 2022.4.2 - Code Execution via RPC Interfaces
CVE-2022-47879HIGHwebappsphp05 May 2023
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load a
41RISK
open
Exploit-DB
Jedox 2022.4.2 - Remote Code Execution via Directory Traversal
CVE-2022-47875HIGHwebappsphp05 May 2023
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex
46RISK
open
Exploit-DB
Jedox 2020.2.5 - Remote Code Execution via Configurable Storage Path
CVE-2022-47878CRITICALwebappsphp05 May 2023
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica
60RISK
open
Exploit-DB
Jedox 2020.2.5 - Remote Code Execution via Executable Groovy-Scripts
CVE-2022-47876CRITICALwebappsphp05 May 2023
The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code v
48RISK
open
Exploit-DB
Jedox 2020.2.5 - Stored Cross-Site Scripting in Log-Module
CVE-2022-47877CRITICALwebappsphp05 May 2023
A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web
48RISK
open
Exploit-DB
MilleGPG5 5.9.2 (Gennaio 2023) - Local Privilege Escalation / Incorrect Access Control
CVE-2023-25438HIGHlocalwindows02 May 2023
An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalat
41RISK
open
Exploit-DB
FS-S3900-24T4S - Privilege Escalation
CVE-2023-30350HIGHlocalhardware02 May 2023
FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin
41RISK
open
Exploit-DB
Sophos Web Appliance 4.3.10.4 - Pre-auth command injection
CVE-2023-1671CRITICALunder attackwebappsphp25 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
Exploit-DB
KodExplorer 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUMwebappsphp25 Apr 2023
kalcaddle KodExplorer cross-site request forgery
33RISK
open
Exploit-DB
PaperCut NG/MG 22.0.4 - Authentication Bypass
CVE-2023-27350CRITICALunder attackransomwarewebappsmultiple25 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Exploit-DB
GDidees CMS 3.9.1 - Local File Disclosure
CVE-2023-27179HIGHwebappsphp20 Apr 2023
GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename paramet
68RISK
open
Exploit-DBVexDay Proof
Bang Resto v1.0 - Stored Cross-Site Scripting (XSS)
CVE-2023-29848MEDIUMwebappsphp20 Apr 2023
Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in
33RISK
open
Exploit-DB
Microsoft Word 16.72.23040900 - Remote Code Execution (RCE)
CVE-2023-28311HIGHremotemultiple20 Apr 2023
Microsoft Word Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
File Replication Pro 7.5.0 - Privilege Escalation/Password reset due Incorrect Access Control
CVE-2023-26918CRITICALlocalwindows20 Apr 2023
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan
48RISK
open
Exploit-DB
Linux Kernel 6.2 - Userspace Processes To Enable Mitigation
CVE-2023-1998MEDIUMlocallinux20 Apr 2023
Spectre v2 SMT mitigations problem in Linux kernel
33RISK
open
Exploit-DBVexDay Proof
Bang Resto v1.0 - 'Multiple' SQL Injection
CVE-2023-29849HIGHwebappsphp20 Apr 2023
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice
41RISK
open
Exploit-DB
Online Computer and Laptop Store 1.0 - Remote Code Execution (RCE)
CVE-2023-1826MEDIUMwebappsphp10 Apr 2023
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
33RISK
open
Exploit-DB
Microsoft Edge (Chromium-based) Webview2 1.0.1661.34 - Spoofing
CVE-2023-24892HIGHlocalmultiple10 Apr 2023
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
41RISK
open
Exploit-DB
Paradox Security Systems IPR512 - Denial Of Service
CVE-2023-24709HIGHdoshardware10 Apr 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISK
open
Exploit-DB
Symantec Messaging Gateway 10.7.4 - Stored Cross-Site Scripting (XSS)
CVE-2022-25630MEDIUMwebappsmultiple08 Apr 2023
An authenticated user can embed malicious content with XSS into the admin group policy page.
33RISK
open
Exploit-DB
Microsoft Excel 365 MSO (Version 2302 Build 16.0.16130.20186) 64-bit - Remote Code Execution (RCE)
CVE-2023-23399HIGHremotemultiple08 Apr 2023
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2022-43939HIGHunder attackwebappsjsp08 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2022-43769HIGHunder attackwebappsjsp08 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open
Exploit-DB
Palo Alto Cortex XSOAR 6.5.0 - Stored Cross-Site Scripting (XSS)
CVE-2022-0020MEDIUMwebappsmultiple08 Apr 2023
Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface
33RISK
open
Exploit-DB
Suprema BioStar 2 v2.8.16 - SQL Injection
CVE-2023-27167MEDIUMwebappsmultiple08 Apr 2023
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs
33RISK
open
Exploit-DB
pfsenseCE v2.6.0 - Anti-brute force protection bypass
CVE-2023-27100CRITICALremotehardware08 Apr 2023
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.