Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC43
Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.
CVE-2023-4911HIGHunder attack17 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC
Proxyshell for Exploiting CVE-2021-34473
CVE-2021-34473CRITICALunder attackransomware17 Oct 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC21
A python based exploit to test out rapid reset attack (CVE-2023-44487)
CVE-2023-44487HIGHunder attack16 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252316 Oct 2023
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC16
testing poc
CVE-2023-41993HIGHunder attack16 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
GitHub PoC1
This repository has the sole purpose of rewriting the CVE-2019-9053 script, which in the original publication is written in Python 2.7. I will be using Python 3.
CVE-2019-905316 Oct 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC5
CVE-2023-41993
CVE-2023-41993HIGHunder attack16 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
GitHub PoC202
po6ix/POC-for-CVE-2023-41993
CVE-2023-41993HIGHunder attack15 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
GitHub PoC
PoC for CVE-2023-4911 LooneyTuneables
CVE-2023-4911HIGHunder attack14 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC6
Confluence Data Center & Server 权限提升漏洞 Exploit
CVE-2023-22515CRITICALunder attackransomware13 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC3
Confluence Broken Access Control
CVE-2023-22515CRITICALunder attackransomware13 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC1
iveresk-CVE-2023-22515
CVE-2023-22515CRITICALunder attackransomware13 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC76
Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)
CVE-2023-44487HIGHunder attack13 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC
Vagebondcur/IMAGE-MAGICK-CVE-2022-44268
CVE-2022-44268MEDIUM13 Oct 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC25
Confluence Unauthorized Administrator User Addition Exploitation Script
CVE-2023-22515CRITICALunder attackransomware12 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC9
delsploit/CVE-2023-27997
CVE-2023-27997CRITICALunder attackransomware12 Oct 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC63
xortigate-cve-2023-27997
CVE-2023-27997CRITICALunder attackransomware12 Oct 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC
Test Script for CVE-2023-44487
CVE-2023-44487HIGHunder attack12 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC
CVE-2023-44487
CVE-2023-44487HIGHunder attack12 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC1
ruycr4ft/CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware12 Oct 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC110
Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具
CVE-2023-22515CRITICALunder attackransomware11 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC56
Proof of concept for DoS exploit
CVE-2023-44487HIGHunder attack11 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC
Security Vulnerability - Kardex Mlog MCC
CVE-2023-22855CRITICAL11 Oct 2023
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 808
53RISK
open
GitHub PoC5
CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server
CVE-2023-22515CRITICALunder attackransomware11 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC18
CVE-2023-4911
CVE-2023-4911HIGHunder attack11 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC8
Poc for CVE-2023-22515
CVE-2023-22515CRITICALunder attackransomware10 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC153
CVE-2023-22515: Confluence Broken Access Control Exploit
CVE-2023-22515CRITICALunder attackransomware10 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC1
WebAccess远程命令执行漏洞(CVE-2017-16720)复现
CVE-2017-1672010 Oct 2023
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within th
35RISK
open
GitHub PoC
CVE-2023-4911
CVE-2023-4911HIGHunder attack10 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC29
hadrian3689/looney-tunables-CVE-2023-4911
CVE-2023-4911HIGHunder attack10 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
previouspage 256 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.