Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,743 exploits
GitHub PoC1
Repo for CVE-2022-46169
CVE-2022-46169CRITICALunder attack20 Mar 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC1
Custom exploit written for enumerating usernames as per CVE-2016-6210
CVE-2016-6210MEDIUM19 Mar 2023
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISK
open
GitHub PoC2
ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook
CVE-2023-23397CRITICALunder attack19 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC9
djackreuter/CVE-2023-23397-PoC
CVE-2023-23397CRITICALunder attack18 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC73
POC for Veeam Backup and Replication CVE-2023-27532
CVE-2023-27532HIGHunder attackransomware18 Mar 2023
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISK
open
GitHub PoC1
CVE-2023-23397 C# PoC
CVE-2023-23397CRITICALunder attack18 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
This script exploits a vulnerability (CVE-2021-25094) in the TypeHub WordPress plugin.
CVE-2021-2509418 Mar 2023
Tatsu < 3.3.12 - Unauthenticated RCE
60RISK
open
GitHub PoC24
CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vulnerability exists, and if it does, will give you a reverse shell.
CVE-2022-22963CRITICALunder attack18 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC
h3x0v3rl0rd/CVE-2016-1531
CVE-2016-153117 Mar 2023
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISK
open
GitHub PoC6
Exploit POC for CVE-2023-23397
CVE-2023-23397CRITICALunder attack17 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC7
Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.
CVE-2023-23397CRITICALunder attack17 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
CVE-2023-23397 Remediation Script (Powershell)
CVE-2023-23397CRITICALunder attack17 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC3
CVE-2023-23397 - Microsoft Outlook Vulnerability
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC4
Python script to create a message with the vulenrability properties set
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC346
api0cradle/CVE-2023-23397-POC-Powershell
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC39
Simple PoC in PowerShell for CVE-2023-23397
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
j0eyv/CVE-2023-23397
CVE-2023-23397CRITICALunder attack16 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Automate JWT Exploit (CVE-2018-0114)
CVE-2018-011416 Mar 2023
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC7
FortiOS buffer overflow vulnerability
CVE-2022-42475CRITICALunder attackransomware16 Mar 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
GitHub PoC159
Exploit for the CVE-2023-23397
CVE-2023-23397CRITICALunder attack15 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC15
Windows Network File System Remote exploit for CVE-2022-30136
CVE-2022-30136CRITICAL15 Mar 2023
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
Proof of concept exploit code for CVE-2020-7388, an unauthenticated RCE as SYSTEM on Sage X3's AdxDSrv Service
CVE-2020-7388CRITICAL15 Mar 2023
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
85RISK
open
GitHub PoC3
An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft
CVE-2021-44228CRITICALunder attackransomware14 Mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Implementation of FOLLINA-CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware14 Mar 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Batch scanning site.
CVE-2020-3187CRITICAL14 Mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
GitHub PoC4
CVE-2022-22963 RCE PoC in python
CVE-2022-22963CRITICALunder attack13 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC4
A Tool for scanning CVE-2017-9841 with multithread
CVE-2017-9841CRITICALunder attack13 Mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC1
Syd-SydneyJr/CVE-2021-45010
CVE-2021-4501013 Mar 2023
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RISK
open
GitHub PoC1
Demonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)
CVE-2022-22965CRITICALunder attack12 Mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
Laravel RCE CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware11 Mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
previouspage 279 / 459next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.