Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,692GitHub PoC 13,812VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
13,812 exploits
GitHub PoC★ 1
PhpMyAdmin 4.0.x—4.6.2 Remote Code Execution Vulnerability (CVE-2016-5734)
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISK
open ↗GitHub PoC★ 19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RISK
open ↗GitHub PoC
[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC★ 3
CVE-2022-36446 - Webmin 1.996 Remote Code Execution
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISK
open ↗GitHub PoC★ 5
CVE-2022-31188 - OpenCV CVAT (Computer Vision Annotation Tool) SSRF
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RISK
open ↗GitHub PoC
This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 35
A real exploit for BitBucket RCE CVE-2022-36804
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open ↗GitHub PoC
Remediation for CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
75RISK
open ↗GitHub PoC★ 23
CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
Redis RCE through Lua Sandbox Escape vulnerability
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open ↗GitHub PoC★ 22
CVE-2022-2586: Linux kernel nft_object UAF
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISK
open ↗GitHub PoC★ 1
0xrobiul/CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 4
Powertek PDU身份绕过
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RISK
open ↗GitHub PoC★ 5
Win10 20H2 LPE for CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability
76RISK
open ↗GitHub PoC★ 2
Zabbix-SAML-Bypass: CVE-2022-23131
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open ↗GitHub PoC
shavchen/CVE-2022-26138
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISK
open ↗GitHub PoC
75ACOL/CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗GitHub PoC
Proof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC★ 2
CVE-2022-24124 exploit
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RISK
open ↗GitHub PoC★ 3
Oracle Weblogic RCE - CVE-2022-2109
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISK
open ↗GitHub PoC★ 5
Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open ↗GitHub PoC
Adobe Acrobat Reader UAF vulnerability Exploit code
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RISK
open ↗GitHub PoC★ 1
Apache Spark RCE - CVE-2022-33891
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open ↗GitHub PoC
CVE-2017-7269 implemented in C#
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC
CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open ↗GitHub PoC
CVE-2017-7269 implemented in python3
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 2
CVE-2022-0492-Container-Escape
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open ↗GitHub PoC
A Docker image vulnerable to CVE-2020-7246.
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.