Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,743 exploits
GitHub PoC
CVE-2021-34527 PrintNightmare PoC
CVE-2021-34527HIGHunder attackransomware20 Aug 2023
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Polkit 0.105-26 0.117-2 - Local Privilege Escalation
CVE-2021-3560HIGHunder attack20 Aug 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC
h4ck0rman/CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware19 Aug 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC9
A PoC exploit for CVE-2018-9995 - DVR Authentication Bypass
CVE-2018-999518 Aug 2023
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC
LearnPress Plugin < 4.2.0 - Unauthenticated SQLi
CVE-2022-45808CRITICAL18 Aug 2023
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
63RISK
open
GitHub PoC2
Python rewrite of the POC for CVE-2023-34634
CVE-2023-3463418 Aug 2023
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green
38RISK
open
GitHub PoC2
Exploit de reverseshell para desserialização em NodeJs (CVE-2017-5941)
CVE-2017-594118 Aug 2023
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
GitHub PoC
LearnPress Plugin < 4.2.0 - Unauthenticated LFI Description
CVE-2022-47615CRITICAL18 Aug 2023
WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to Local File Inclusion
63RISK
open
GitHub PoC27
3tternp/CVE-2023-21554
CVE-2023-21554CRITICAL17 Aug 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open
GitHub PoC
asepsaepdin/CVE-2022-21907
CVE-2022-21907CRITICAL17 Aug 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Ivanti Avalanche v6.4.0.0 RCE POC
CVE-2023-32560HIGH17 Aug 2023
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
GitHub PoC
tianstcht/CVE-2023-2033
CVE-2023-2033HIGHunder attack17 Aug 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC5
PoC exploit for file upload vulnerability in BoidCMS version <=2.0.0
CVE-2023-3883616 Aug 2023
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header t
50RISK
open
GitHub PoC
GitHub repository for CVE-2023-3460 POC
CVE-2023-346015 Aug 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC130
mistymntncop/CVE-2023-3079
CVE-2023-3079HIGHunder attack15 Aug 2023
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC4
CVE-2023-33242 PoC
CVE-2023-33242CRITICAL15 Aug 2023
Lindell17 TSS Abort Mishandling
48RISK
open
GitHub PoC
This is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/zerologon_tester.py) and the tool evil-winrm to get a shell.
CVE-2020-1472MEDIUMunder attackransomware14 Aug 2023
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC8
Local privilege escalation exploit for Android Binder bug CVE-2020-0041 (Pixel 3a)
CVE-2020-0041HIGHunder attack14 Aug 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
GitHub PoC2
CVE-2022-44268_By_Kyokito
CVE-2022-44268MEDIUM13 Aug 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC1
A PoC exploit for CVE-2021-34621 - WordPress Privilege Escalation
CVE-2021-34621CRITICAL12 Aug 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
GitHub PoC
CVE-2023-4174 PoC
CVE-2023-4174LOW11 Aug 2023
mooSocial mooStore cross site scripting
43RISK
open
GitHub PoC1
CVE-2023-33246 POC
CVE-2023-33246CRITICALunder attack11 Aug 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC
yosef0x01/CVE-2023-21752
CVE-2023-21752HIGH10 Aug 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC3
Prestashop fix vulnerability CVE-2023-39526 & CVE-2023-39527
CVE-2023-39526CRITICAL10 Aug 2023
PrestaShopSQL manager vulnerability (potential RCE)
48RISK
open
GitHub PoC65
mandiant/citrix-ioc-scanner-cve-2023-3519
CVE-2023-3519CRITICALunder attackransomware10 Aug 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
CVE-2021-34621CRITICAL09 Aug 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
GitHub PoC52
PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2
CVE-2023-38408CRITICAL09 Aug 2023
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC9
CVE exploitation for WebKit jsc CVE-2018-4416
CVE-2018-441607 Aug 2023
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RISK
open
GitHub PoC
Campcodes Online Matrimonial Website System 3.3 Cross Site Scripting
CVE-2023-3911507 Aug 2023
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RISK
open
GitHub PoC
Original Exploit Source: https://www.exploit-db.com/exploits/46635
CVE-2019-905307 Aug 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
previouspage 263 / 459next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.