Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
13,743 exploits
GitHub PoC★ 19
Exploits for a heap overflow in MiniDLNA <=1.3.2 (CVE-2023-33476)
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by
48RISK
open ↗GitHub PoC★ 69
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open ↗GitHub PoC
overgrowncarrot1/CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open ↗GitHub PoC★ 57
Openfire Console Authentication Bypass Vulnerability with RCE plugin
Openfire administration console authentication bypass
100RISK
open ↗GitHub PoC★ 7
CVE-2023-24078 for FuguHub / BarracudaDrive
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISK
open ↗GitHub PoC★ 23
FortiOS 管理界面中的堆内存下溢导致远程代码执行
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0
53RISK
open ↗GitHub PoC★ 1
CVE-2023-24078 for FuguHub / BarracudaDrive
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the c
53RISK
open ↗GitHub PoC★ 6
Repository with everything I have tracking the impact of MOVEit CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open ↗GitHub PoC★ 4
Joomla未授权访问漏洞
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 15
SolarView Compact through 6.00 downloader.php commands injection (RCE) nuclei-templates
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open ↗GitHub PoC★ 134
Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open ↗GitHub PoC
CVE-2023-34600
Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
53RISK
open ↗GitHub PoC★ 27
POC FortiOS SSL-VPN buffer overflow vulnerability
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open ↗GitHub PoC
Samba 3.0.20
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗GitHub PoC★ 2
5rGJ5aCh5oCq5YW9/CVE-2023-32315exp
Openfire administration console authentication bypass
100RISK
open ↗GitHub PoC
Exploit for CVE-2022-44136 for chcking security of your site
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISK
open ↗GitHub PoC
ohnonoyesyes/CVE-2023-32315
Openfire administration console authentication bypass
100RISK
open ↗GitHub PoC★ 1
y0d3n/CVE-2014-0094
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISK
open ↗GitHub PoC★ 6
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open ↗GitHub PoC★ 229
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware
100RISK
open ↗GitHub PoC
Sonatype Nexus 3.21.01 - Remote Code Execution (Authenticated - Updated)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open ↗GitHub PoC
Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress in Python Version
Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
60RISK
open ↗GitHub PoC★ 2
python program to exploit CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
Python 2.7
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open ↗GitHub PoC★ 64
CVE-2023-34362: MOVEit Transfer Unauthenticated RCE
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open ↗GitHub PoC★ 77
CVE-2023-20963 PoC (Android WorkSource parcel/unparcel logic mismatch)
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RISK
open ↗GitHub PoC★ 3
A script, written in golang. POC for CVE-2023-25157
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.