Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,743 exploits
GitHub PoC1
An exploitation of CVE-2022-30190 (Follina)
CVE-2022-30190HIGHunder attackransomware02 May 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Este es un código del exploit CVE-2022-46169, que recree utilizando Python3! Si por ahí estás haciendo una máquina de HTB, esto te puede ser útil... 🤞✨
CVE-2022-46169CRITICALunder attack02 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC1
Improved PoC for Unauthenticated RCE on Cacti <= 1.2.22 - CVE-2022-46169
CVE-2022-46169CRITICALunder attack02 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC42
This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.
CVE-2022-46169CRITICALunder attack01 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC3
Exploit for cacti version 1.2.22
CVE-2022-46169CRITICALunder attack01 May 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Zoo1sondv/CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware01 May 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
tuankiethkt020/Phat-hien-CVE-2017-8464
CVE-2017-8464HIGHunder attack01 May 2023
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALunder attack30 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
gretchenfrage/CVE-2023-2033-analysis
CVE-2023-2033HIGHunder attack30 Apr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC2
Akash7350/CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware30 Apr 2023
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Cisco r042 research
CVE-2023-20025CRITICAL30 Apr 2023
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers co
48RISK
open
GitHub PoC1
zPrototype/CVE-2023-29809
CVE-2023-29809CRITICAL30 Apr 2023
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RISK
open
GitHub PoC
check cve-2022-0847
CVE-2022-0847HIGHunder attack30 Apr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
MrE-Fog/CVE-2014-0160-Chrome-Plugin
CVE-2014-0160HIGHunder attack30 Apr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
PoC for CVE-2022-46169 that affects Cacti 1.2.22 version
CVE-2022-46169CRITICALunder attack29 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
zPrototype/CVE-2023-29983
CVE-2023-29983MEDIUM29 Apr 2023
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RISK
open
GitHub PoC37
Cobalt Strike 4.4 猪猪版 去暗桩 去流量特征 beacon仿造真实API服务 修补CVE-2022-39197补丁
CVE-2022-39197MEDIUMunder attack28 Apr 2023
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
GitHub PoC
CVE-2020-14882 rewritten in PowerShell
CVE-2020-14882CRITICALunder attack28 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
This repository contains a python script that will handle the majority of the dompdf cached font exploit (CVE-2022-28368), all you need to do is create the request
CVE-2022-2836828 Apr 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISK
open
GitHub PoC
PrestaShop <1.7.8.9 Fix for CVE-2023-30839 and CVE-2023-30545
CVE-2023-30839CRITICAL27 Apr 2023
PrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager"
48RISK
open
GitHub PoC11
Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具
CVE-2023-27524HIGHunder attack27 Apr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC3
Apache Superset Auth Bypass Vulnerability CVE-2023-27524.
CVE-2023-27524HIGHunder attack27 Apr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC
natceil/cve-2022-42475
CVE-2022-42475CRITICALunder attackransomware27 Apr 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
GitHub PoC6
A Python PoC of CVE-2022-21661, inspired from z92g's Go PoC
CVE-2022-21661HIGH27 Apr 2023
SQL injection in WordPress
78RISK
open
GitHub PoC19
A collection of resources and information about CVE-2023-2033
CVE-2023-2033HIGHunder attack26 Apr 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC2
A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.
CVE-2022-0847HIGHunder attack26 Apr 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
ShyTangerine/cve-2021-26855
CVE-2021-26855CRITICALunder attackransomware25 Apr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Check for CVE-2014-0160
CVE-2014-0160HIGHunder attack25 Apr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
UnrealIRCd 3.2.8.1 backdoor command execution exploit in Python 3 (CVE-2010-2075).
CVE-2010-207525 Apr 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open
GitHub PoC25
CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5
CVE-2023-22621CRITICAL25 Apr 2023
Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitra
85RISK
open
previouspage 274 / 459next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.