Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
13,812 exploits
GitHub PoC
devengpk/CVE-2022-36804
CVE-2022-36804HIGHunder attack20 Dec 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC6
Proof of concept of CVE-2022-24086
CVE-2022-24086CRITICALunder attack20 Dec 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
GitHub PoC1
devengpk/CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware18 Dec 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC
By passing an overly large string when invoking nethack, it is possible to corrupt memory. jnethack and falconseye are also prone to this vulnerability.
CVE-2003-035817 Dec 2022
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allow
23RISK
open
GitHub PoC
Drupal CVE-2018-7600 RCE Pseudo-Shell PoC
CVE-2018-7600CRITICALunder attackransomware17 Dec 2022
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
CVE-2022-46169 - Cacti Blind Remote Code Execution (Pre-Auth)
CVE-2022-46169CRITICALunder attack16 Dec 2022
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Chương trình theo dõi, giám sát lưu lượng mạng được viết bằng Python, nó sẽ đưa ra cảnh báo khi phát hiện tấn công CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware16 Dec 2022
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
CVE-2020-0796-利用工具
CVE-2020-0796CRITICALunder attackransomware15 Dec 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC3
An exploit for CVE-2012-2982 implemented in Rust
CVE-2012-298215 Dec 2022
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
GitHub PoC
A Proof of Concept for the CVE-2021-27928 flaw exploitation
CVE-2021-2792814 Dec 2022
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RISK
open
GitHub PoC3
Improper access control in SAP NetWeaver Process Integration
CVE-2022-41272CRITICAL13 Dec 2022
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se
48RISK
open
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2021-1497CRITICALunder attack13 Dec 2022
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2019-11510CRITICALunder attackransomware13 Dec 2022
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RISK
open
GitHub PoC3
cve-2019-11510, cve-2019-19781, cve-2020-5902,               cve-2021-1497, cve-2021-20090, cve-2021-22006, cve-2021-22205, cve-2021-26084, cve-2021-26855, cve-2021-26857, cve-2021–26857, cve-2021–26858, cve-2021–26865
CVE-2020-5902CRITICALunder attackransomware13 Dec 2022
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC
KaviDk/CVE-2019-6447-in-Mobile-Application
CVE-2019-644712 Dec 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC
Educational Follina PoC Tool
CVE-2022-30190HIGHunder attackransomware12 Dec 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
devengpk/CVE-2022-22965
CVE-2022-22965CRITICALunder attack12 Dec 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
CVE-2020-16846
CVE-2020-16846CRITICALunder attack12 Dec 2022
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RISK
open
GitHub PoC7
CVE-2021-3129 Exploit Checker By ./MrMad
CVE-2021-3129CRITICALunder attackransomware10 Dec 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC20
text4shell(CVE-2022-42889) BurpSuite Scanner
CVE-2022-4288909 Dec 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
Scan IP ranges for IP's vulnerable to the F5 Big IP exploit (CVE-2022-1388)
CVE-2022-1388CRITICALunder attackransomware09 Dec 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC89
[PoC] Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom)
CVE-2022-45025CRITICAL09 Dec 2022
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi
60RISK
open
GitHub PoC9
CVE-2022-36537
CVE-2022-36537HIGHunder attackransomware09 Dec 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISK
open
GitHub PoC36
POC of CVE-2022-36537
CVE-2022-36537HIGHunder attackransomware09 Dec 2022
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISK
open
GitHub PoC47
CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.
CVE-2022-46169CRITICALunder attack08 Dec 2022
Unauthenticated Command Injection
100RISK
open
GitHub PoC1
CVE-2022-42889 - Text4Shell exploit
CVE-2022-4288907 Dec 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALunder attack07 Dec 2022
Unauthenticated Command Injection
100RISK
open
GitHub PoC5
PHPunit Checker CVE-2017-9841 By MrMad
CVE-2017-9841CRITICALunder attack07 Dec 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC
For CVE-2022-33891 Apache Spark: Emulation and Detection by West Shepherd
CVE-2022-33891HIGHunder attack06 Dec 2022
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
GitHub PoC1
amitlttwo/CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware06 Dec 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
previouspage 290 / 461next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.