Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
21,662 exploits
Referência
CVE-2010-1946
Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled,
23RISK
open
Referência
CVE-2010-1946
Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled,
23RISK
open
Referência
CVE-2021-36711
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
28RISK
open
Referência
CVE-2021-38759
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain a
28RISK
open
Referência
CVE-2021-39312
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RISK
open
Referência
CVE-2021-39316
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RISK
open
Referência
Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure
CVE-2021-39327MEDIUMwebappsphp
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RISK
open
Referência
CVE-2021-4034
CVE-2021-4034HIGHunder attack
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Referência
CVE-2021-4034
CVE-2021-4034HIGHunder attack
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Referência
CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
Referência
CVE-2021-40964
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RISK
open
Referência
CVE-2021-41318
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RISK
open
Referência
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Referência
CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
Referência
CVE-2021-35464
CVE-2021-35464CRITICALunder attackransomware
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open
Referência
CVE-2021-35464
CVE-2021-35464CRITICALunder attackransomware
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RISK
open
Referência
CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
Referência
CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
Referência
CVE-2023-22518
CVE-2023-22518CRITICALunder attackransomware
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open
Referência
CVE-2021-1498
CVE-2021-1498CRITICALunder attack
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open
Referência
CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Referência
CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Referência
CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Referência
CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Referência
CVE-2023-0669
CVE-2023-0669HIGHunder attackransomware
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
Referência
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Referência
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Referência
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Referência
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Referência
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
previouspage 251 / 723next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.