Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,743 exploits
GitHub PoC1
rwincey/cve-2023-3519
CVE-2023-3519CRITICALunder attackransomware06 Aug 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC2
Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.
CVE-2023-22809HIGH06 Aug 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC
MrE-Fog/jboss-_CVE-2017-12149
CVE-2017-12149CRITICALunder attackransomware06 Aug 2023
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC1
Quick PoC checker for common configurations that might be available via directory traversal due to CVE-2013-3827
CVE-2013-382705 Aug 2023
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RISK
open
GitHub PoC2
Exim < 4.90.1 RCE Vulnerability remake for Python3 with arguments passed from CLI
CVE-2018-6789CRITICALunder attackransomware05 Aug 2023
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
GitHub PoC3
This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically.
CVE-2021-22555HIGHunder attack05 Aug 2023
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC1
passwa11/CVE-2023-3519
CVE-2023-3519CRITICALunder attackransomware05 Aug 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC2
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
CVE-2023-2732CRITICAL05 Aug 2023
MStore API <= 3.9.2 - Authentication Bypass
75RISK
open
GitHub PoC1
isacaya/CVE-2019-11358
CVE-2019-1135805 Aug 2023
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
CVE-2013-2251CRITICALunder attack04 Aug 2023
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISK
open
GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
CVE-2020-17530CRITICALunder attack04 Aug 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
CVE-2023-35082CRITICALunder attackransomware04 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISK
open
GitHub PoC2
CVE-2023-37979 PoC and Checker
CVE-2023-37979HIGH04 Aug 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
61RISK
open
GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
CVE-2022-2696504 Aug 2023
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RISK
open
GitHub PoC4
Exploit CVE-2021-41773 and CVE-2021-42013
CVE-2021-41773HIGHunder attackransomware02 Aug 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC64
mistymntncop/CVE-2023-2033
CVE-2023-2033HIGHunder attack02 Aug 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC3
Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension.
CVE-2020-25213CRITICALunder attack02 Aug 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC1
asepsaepdin/CVE-2010-1240
CVE-2010-124002 Aug 2023
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
GitHub PoC
overgrowncarrot1/DejaVu-CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware02 Aug 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
726232111/CVE-2023-28252
CVE-2023-28252HIGHunder attackransomware02 Aug 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
CVE-2020-0688 modified exploit for Exchange 2010
CVE-2020-0688HIGHunder attackransomware02 Aug 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC2
Nmap NSE script to dump / test Solarwinds CVE-2023-23333 vulnerability
CVE-2023-23333CRITICAL01 Aug 2023
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open
GitHub PoC
CVE-2022-1388 - F5 Router RCE Replica
CVE-2022-1388CRITICALunder attackransomware01 Aug 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
Nmap script to exploit CVE-2023-35078 - Mobile Iron Core
CVE-2023-35078CRITICALunder attackransomware01 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC14
Mehran-Seifalinia/CVE-2023-37979
CVE-2023-37979HIGH01 Aug 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
61RISK
open
GitHub PoC
Unauthenticated Command Injection in Cacti <= 1.2.22
CVE-2022-46169CRITICALunder attack01 Aug 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC3
Perform With Mass Remote Code Execution In SPIP Version (4.2.1)
CVE-2023-27372CRITICAL31 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC
timsonner/cve-2014-0160-heartbleed
CVE-2014-0160HIGHunder attack31 Jul 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC5
Tools to scanner & exploit cve-2023-35078
CVE-2023-35078CRITICALunder attackransomware31 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC
Easy and non-intrusive script to check for CVE-2023-35078
CVE-2023-35078CRITICALunder attackransomware31 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
previouspage 264 / 459next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.