Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
13,743 exploits
GitHub PoC
CHINA-china/MinIO_CVE-2023-28432_EXP
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 3
CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open ↗GitHub PoC★ 3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
Unauthenticated Command Injection
100RISK
open ↗GitHub PoC★ 1
F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open ↗GitHub PoC
nik0nz7/CVE-2020-14882
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗GitHub PoC
Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0
Unauthenticated Command Injection
100RISK
open ↗GitHub PoC
FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
53RISK
open ↗GitHub PoC★ 3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISK
open ↗GitHub PoC★ 1
Rust-based exploit for the CVE-2022-22963 vulnerability
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 33
Perform With Mass Exploiter In Joomla 4.2.8.
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC
ReachabilityOrg/cve-2022-42889-text4shell-docker
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open ↗GitHub PoC
Ge-Per/Scanner-CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC
jedai47/CVE-2017-16994
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RISK
open ↗GitHub PoC★ 2
POC,EXP,chatGPT for me
Apache MINA SSHD: Java unsafe deserialization vulnerability
48RISK
open ↗GitHub PoC★ 1
POC,EXP,chatGPT for me,只能给一些思路,全部不可用
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
48RISK
open ↗GitHub PoC
jedai47/CVE-2018-7273
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RISK
open ↗GitHub PoC
Checker help to verify created account or find it's mandat
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open ↗GitHub PoC
jedai47/cve-2018-17182
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RISK
open ↗GitHub PoC★ 2
DarokNET/CVE-2023-27100
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open ↗GitHub PoC★ 1
LHXHL/Minio-CVE-2023-28432
Minio Information Disclosure in Cluster Deployment
100RISK
open ↗GitHub PoC★ 6
CVE-2023-22809 Linux Sudo
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open ↗GitHub PoC★ 1
CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC
BaconCriCRi/PoC-CVE-2022-4939-
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
48RISK
open ↗GitHub PoC★ 8
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open ↗GitHub PoC
qaisarafridi/cve-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open ↗GitHub PoC★ 3
brosck/CVE-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open ↗GitHub PoC★ 2
CVE-2014-6287
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.