Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,743 exploits
GitHub PoC3
Perform With Mass Remote Code Execution In SPIP Version (4.2.1)
CVE-2023-27372CRITICAL31 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC
cashapp323232/CVE-2023-2868CVE-2023-2868
CVE-2023-2868CRITICALunder attack30 Jul 2023
Remote Code injection in Barracuda Email Security Gateway
100RISK
open
GitHub PoC
Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)
CVE-2022-26134CRITICALunder attackransomware30 Jul 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
#comeonits2023 #ie9 #Storm-0978
CVE-2023-36884HIGHunder attackransomware30 Jul 2023
Windows Search Remote Code Execution Vulnerability
93RISK
open
GitHub PoC117
CVE-2023-35078 Remote Unauthenticated API Access Vulnerability Exploit POC
CVE-2023-35078CRITICALunder attackransomware29 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC5
Proof of concept script to check if the site is vulnerable to CVE-2023-35078
CVE-2023-35078CRITICALunder attackransomware29 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC9
CVE-2023-22884 PoC
CVE-2023-22884CRITICAL29 Jul 2023
Apache Airflow, Apache Airflow MySQL Provider: Arbitrary file read via MySQL provider in Apache Airflow
53RISK
open
GitHub PoC
Pseudo shell for CVE-2013-0156.
CVE-2013-015629 Jul 2023
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
GitHub PoC17
Voyag3r-Security/CVE-2023-1389
CVE-2023-1389HIGHunder attack28 Jul 2023
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISK
open
GitHub PoC2
ridsoliveira/Fix-CVE-2023-36884
CVE-2023-36884HIGHunder attackransomware28 Jul 2023
Windows Search Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
JohnGilbert57/CVE-2021-4034-Capture-the-flag
CVE-2021-4034HIGHunder attack28 Jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
Exploit for the vulnerability of Ultimate Member Plugin.
CVE-2023-346027 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC2
CVE-2021-3129 | Laravel Debug Mode Vulnerability
CVE-2021-3129CRITICALunder attackransomware27 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
Laravel RCE (CVE-2021-3129)
CVE-2021-3129CRITICALunder attackransomware26 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
simple program for joomla scanner CVE-2023-23752 with target list
CVE-2023-23752MEDIUMunder attack26 Jul 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE
CVE-2021-22204MEDIUMunder attack25 Jul 2023
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC2
Python script to exploit PlaySMS before 1.4.3
CVE-2020-8644CRITICALunder attack25 Jul 2023
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RISK
open
GitHub PoC1
Learn what is BlueJam CVE-2017-0781
CVE-2017-078124 Jul 2023
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RISK
open
GitHub PoC1
CVE-2022-23305 Log4J JDBCAppender SQl injection POC
CVE-2022-23305CRITICAL24 Jul 2023
SQL injection in JDBC Appender in Apache Log4j V1
60RISK
open
GitHub PoC46
A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.
CVE-2017-7921CRITICALunder attack24 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC1
ImageMagick Arbitrary Read Files - CVE-2022-44268
CVE-2022-44268MEDIUM23 Jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC11
CVE-2023-3519 vuln for nuclei scanner
CVE-2023-3519CRITICALunder attackransomware21 Jul 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC
CVE-2023-3519
CVE-2023-3519CRITICALunder attackransomware21 Jul 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC228
RCE exploit for CVE-2023-3519
CVE-2023-3519CRITICALunder attackransomware21 Jul 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC1
NetScaler (Citrix ADC) CVE-2023-3519 Scanner
CVE-2023-3519CRITICALunder attackransomware21 Jul 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC13
mr-r3b00t/CVE-2023-3519
CVE-2023-3519CRITICALunder attackransomware21 Jul 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC2
A PoC exploit for CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP)
CVE-2015-216620 Jul 2023
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5
43RISK
open
GitHub PoC52
Citrix Scanner for CVE-2023-3519
CVE-2023-3519CRITICALunder attackransomware20 Jul 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC86
Accurately fingerprint and detect vulnerable (and patched!) versions of Netscaler / Citrix ADC to CVE-2023-3519
CVE-2023-3519CRITICALunder attackransomware20 Jul 2023
Unauthenticated remote code execution
100RISK
open
GitHub PoC4
A PoC exploit for CVE-2010-4231 - Directory Traversal Vulnerability in Camtron and TecVoz IP Cameras.
CVE-2010-423120 Jul 2023
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera an
43RISK
open
previouspage 265 / 459next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.