Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,743 exploits
GitHub PoC
CHINA-china/MinIO_CVE-2023-28432_EXP
CVE-2023-28432HIGHunder attack13 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC3
CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)
CVE-2022-38181HIGHunder attack13 Apr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
GitHub PoC3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
CVE-2022-46169CRITICALunder attack13 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
hh-hunter/ml-CVE-2023-1177
CVE-2023-1177CRITICAL13 Apr 2023
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
GitHub PoC1
F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800
CVE-2022-1388CRITICALunder attackransomware12 Apr 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
nik0nz7/CVE-2020-14882
CVE-2020-14882CRITICALunder attack11 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0
CVE-2022-46169CRITICALunder attack11 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow
CVE-2023-25234CRITICAL11 Apr 2023
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
53RISK
open
GitHub PoC3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
CVE-2023-30256MEDIUM10 Apr 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISK
open
GitHub PoC1
Rust-based exploit for the CVE-2022-22963 vulnerability
CVE-2022-22963CRITICALunder attack10 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
CVE-2023-28432HIGHunder attack09 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC33
Perform With Mass Exploiter In Joomla 4.2.8.
CVE-2023-23752MEDIUMunder attack09 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
ReachabilityOrg/cve-2022-42889-text4shell-docker
CVE-2022-4288908 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
Ge-Per/Scanner-CVE-2023-23752
CVE-2023-23752MEDIUMunder attack08 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
jedai47/CVE-2017-16994
CVE-2017-1699407 Apr 2023
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISK
open
GitHub PoC2
POC,EXP,chatGPT for me
CVE-2022-45047CRITICAL07 Apr 2023
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RISK
open
GitHub PoC1
POC,EXP,chatGPT for me,只能给一些思路,全部不可用
CVE-2022-21306CRITICAL07 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
48RISK
open
GitHub PoC2
Clone from gist
CVE-2023-29017CRITICAL07 Apr 2023
vm2 Sandbox Escape vulnerability
60RISK
open
GitHub PoC
jedai47/CVE-2018-7273
CVE-2018-727307 Apr 2023
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISK
open
GitHub PoC
Checker help to verify created account or find it's mandat
CVE-2020-6287CRITICALunder attack07 Apr 2023
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC
jedai47/cve-2018-17182
CVE-2018-1718207 Apr 2023
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open
GitHub PoC2
DarokNET/CVE-2023-27100
CVE-2023-27100CRITICAL07 Apr 2023
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open
GitHub PoC1
LHXHL/Minio-CVE-2023-28432
CVE-2023-28432HIGHunder attack06 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC6
CVE-2023-22809 Linux Sudo
CVE-2023-22809HIGH06 Apr 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC1
CVE-2023-23752
CVE-2023-23752MEDIUMunder attack06 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
BaconCriCRi/PoC-CVE-2022-4939-
CVE-2022-4939CRITICAL06 Apr 2023
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
48RISK
open
GitHub PoC8
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
CVE-2023-0669HIGHunder attackransomware06 Apr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
GitHub PoC
qaisarafridi/cve-2021-3129
CVE-2021-3129CRITICALunder attackransomware06 Apr 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC3
brosck/CVE-2006-3392
CVE-2006-339204 Apr 2023
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
GitHub PoC2
CVE-2014-6287
CVE-2014-6287CRITICALunder attack04 Apr 2023
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
previouspage 276 / 459next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.