Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
13,812 exploits
GitHub PoC7
修改版CVE-2022-0847
CVE-2022-0847HIGHunder attack21 Nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
REMOTE CODE EXECUTION
CVE-2020-23584CRITICAL20 Nov 2022
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes ar
60RISK
open
GitHub PoC
REMOTE CODE EXECUTION found in "OPTILINK OP-XT71000N".
CVE-2020-23583CRITICAL20 Nov 2022
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary
48RISK
open
GitHub PoC
ARBITAR FILE UPLOAD LEADS TO "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor , Escalation of Privileges, etc".
CVE-2020-23591CRITICAL20 Nov 2022
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker t
48RISK
open
GitHub PoC8
A Command Line based python tool for exploit Zero-Day vulnerability in MSDT (Microsoft Support Diagnostic Tool) also know as 'Follina' CVE-2022-30190.
CVE-2022-30190HIGHunder attackransomware19 Nov 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
CVE-2022-0441 - MasterStudy LMS 2.7.6
CVE-2022-044118 Nov 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open
GitHub PoC
Vulnerable configuration Apache HTTP Server version 2.4.49/2.4.50
CVE-2021-42013CRITICALunder attackransomware18 Nov 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
wordpress docker
CVE-2016-10033CRITICALunder attack18 Nov 2022
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC
Vulnerable configuration Apache HTTP Server version 2.4.49
CVE-2021-41773HIGHunder attackransomware18 Nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Abdulazizalsewedy/CVE-2021-29447
CVE-2021-29447HIGH17 Nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC1
A write-up of my (so far inconclusive) look into CVE-2022-31691
CVE-2022-31691CRITICAL17 Nov 2022
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI
48RISK
open
GitHub PoC2
A massive scanner for CVE-2021-34473 Microsoft Exchange Windows Vulnerability
CVE-2021-34473CRITICALunder attackransomware16 Nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Resources required for building Pluralsight CVE-2022-0847 lab
CVE-2022-0847HIGHunder attack16 Nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC4
FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)
CVE-2022-2463715 Nov 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open
GitHub PoC1
qq87234770/CVE-2022-22947
CVE-2022-22947CRITICALunder attack15 Nov 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC3
A Golang program to automate the execution of CVE-2021-29447
CVE-2021-29447HIGH15 Nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC3
Social WarFare Plugin (<=3.5.2) Remote Code Execution
CVE-2019-9978MEDIUMunder attack15 Nov 2022
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC7
mega8bit/exploit_cve-2021-29447
CVE-2021-29447HIGH14 Nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC7
RCE exploit for WSO2
CVE-2022-29464CRITICALunder attackransomware14 Nov 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC3
Microsoft Exchange Server Remote Code Execution Vulnerability.
CVE-2022-41082HIGHunder attackransomware14 Nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
fall2022 secure coding CVE-2019-13272 : Linux Kernel Improper Privilege Management Vulnerability
CVE-2019-13272HIGHunder attack14 Nov 2022
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC1
CyberKimathi/Py3-CVE-2017-0785
CVE-2017-078513 Nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC257
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2017-12615HIGHunder attackransomware13 Nov 2022
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC257
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2020-1938CRITICALunder attack13 Nov 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
ivilpez/cve-2017-16995.c
CVE-2017-1699512 Nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC359
Unsigned driver loader using CVE-2018-19320
CVE-2018-19320HIGHunder attackransomware12 Nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RISK
open
GitHub PoC4
Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.
CVE-2021-29447HIGH11 Nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC109
Zimbra <9.0.0.p27 RCE
CVE-2022-41352CRITICALunder attack11 Nov 2022
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISK
open
GitHub PoC
Joanmei/CVE-2017-0785
CVE-2017-078510 Nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC
SPRING DATA REST CVE-2017-8046 DEMO
CVE-2017-804610 Nov 2022
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RISK
open
previouspage 292 / 461next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.