Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,743 exploits
GitHub PoC
CVE-2023-3460
CVE-2023-346011 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC1
Python script that generates pfs payloads to exploit CVE-2022-4510
CVE-2022-4510HIGH11 Jul 2023
Path Traversal in binwalk
46RISK
open
GitHub PoC
asepsaepdin/CVE-2021-3560
CVE-2021-3560HIGHunder attack10 Jul 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC
asepsaepdin/CVE-2021-4034
CVE-2021-4034HIGHunder attack10 Jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC6
asepsaepdin/CVE-2023-22809
CVE-2023-22809HIGH10 Jul 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC4
A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.
CVE-2023-32235HIGH09 Jul 2023
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISK
open
GitHub PoC
Mass CVE-2023-3460.
CVE-2023-346009 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC1
Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.
CVE-2022-0847HIGHunder attack09 Jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
bthnrml/guncel-cve-2019-9053.py
CVE-2019-905309 Jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC10
POC for CVE-2023-34362 affecting MOVEit Transfer
CVE-2023-34362CRITICALunder attackransomware09 Jul 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
GitHub PoC
Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10
CVE-2022-24715HIGH08 Jul 2023
Arbitrary code execution for authenticated users in Icinga Web 2
46RISK
open
GitHub PoC2
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL
CVE-2023-3616308 Jul 2023
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code
23RISK
open
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code via the MTAgentService component
CVE-2023-3616408 Jul 2023
20RISK
open
GitHub PoC
An issue in MiniTool Partition Wizard ShadowMaker v.12.7 allows an attacker to execute arbitrary code and gain privileges via the SchedulerService.exe component.
CVE-2023-3616508 Jul 2023
20RISK
open
GitHub PoC
pitufo1721/CVE-2025-55182-GodzillaMemoryShell
CVE-2025-55182CRITICALunder attackransomware07 Jul 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
rizqimaulanaa/CVE-2023-3460
CVE-2023-346007 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC5
CVE-2023-32315-Openfire-Bypass
CVE-2023-32315HIGHunder attack07 Jul 2023
Openfire administration console authentication bypass
100RISK
open
GitHub PoC
LoaiEsam37/CVE-2023-2982
CVE-2023-2982CRITICAL07 Jul 2023
WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
75RISK
open
GitHub PoC
Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.
CVE-2015-157807 Jul 2023
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISK
open
GitHub PoC8
An eBPF program to detect attacks on CVE-2022-0847
CVE-2022-0847HIGHunder attack06 Jul 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC35
Exploit for CVE-2023-3460. Unauthorized admin access for Ultimate Member plugin < v2.6.7
CVE-2023-346005 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
GitHub PoC6
This is a PoC for CVE-2023-27372 which spawns a fully interactive shell.
CVE-2023-27372CRITICAL05 Jul 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC
This is the Updated Python3 exploit for CVE-2019-9053
CVE-2019-905304 Jul 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC2
CVE-2017-7921 EXPLOIT
CVE-2017-7921CRITICALunder attack04 Jul 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!
CVE-2023-39362HIGH03 Jul 2023
Authenticated command injection in SNMP options of a Device
63RISK
open
GitHub PoC3
Fix WinVerifyTrust Signature Validation Vulnerability, CVE-2013-3900, QID-378332
CVE-2013-3900MEDIUMunder attack03 Jul 2023
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC13
PoC of Imagemagick's Arbitrary File Read
CVE-2022-44268MEDIUM03 Jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC4
Wordpress CVE-2023-32243
CVE-2023-32243CRITICAL03 Jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
GitHub PoC6
Perform With Massive Openfire Unauthenticated Users
CVE-2023-32315HIGHunder attack02 Jul 2023
Openfire administration console authentication bypass
100RISK
open
GitHub PoC1
Expoit for CVE-2022-44268
CVE-2022-44268MEDIUM02 Jul 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
previouspage 267 / 459next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.