Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
13,885 exploits
GitHub PoC4
Zyxel 防火墙未经身份验证的远程命令注入
CVE-2022-30525CRITICALunder attack13 May 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC13
Tool for CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware13 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
testaross4/CVE-2007-2447
CVE-2007-244713 May 2022
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC33
Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)批量检测脚本
CVE-2022-30525CRITICALunder attack13 May 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC22
Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)
CVE-2022-30525CRITICALunder attack13 May 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC2
Nuclei Template for CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware12 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC6
Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services
CVE-2022-26923HIGHunder attack12 May 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC13
F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB
CVE-2022-1388CRITICALunder attackransomware12 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC2
Essay (and PoCs) about CVE-2021-41773, a remote code execution vulnerability in Apache 2.4.49 🕸️
CVE-2021-41773HIGHunder attackransomware12 May 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2021-41773 Shodan scanner
CVE-2021-41773HIGHunder attackransomware12 May 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2020-0688_Microsoft Exchange default MachineKeySection deserialize vulnerability
CVE-2020-0688HIGHunder attackransomware12 May 2022
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC1
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
CVE-2013-471011 May 2022
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RISK
open
GitHub PoC7
A Zeek package to detect CVE-2022-26937, a vulnerability in the Network Lock Manager (NLM) protocol in Windows NFS server.
CVE-2022-26937CRITICAL11 May 2022
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC5
AmirHoseinTangsiriNET/CVE-2022-1388-Scanner
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
Research and proof of concept related to CVE-2022-1388.
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC2
CVE-2022-1388 Scanner
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
ShaikUsaf/external_expact_AOSP10_r33_CVE-2022-25315
CVE-2022-25315CRITICAL11 May 2022
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
48RISK
open
GitHub PoC1
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
CVE-2012-663611 May 2022
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RISK
open
GitHub PoC
Satheesh575555/external_expat_AOSP10_r33_CVE-2022-23852
CVE-2022-23852CRITICAL10 May 2022
Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_
48RISK
open
GitHub PoC1
An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown coding-list inside the HTTP Protocol Stack (http.sys) to process packets, resulting in a kernel crash.
CVE-2022-21907CRITICAL10 May 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC30
Proof of concept exploit for CVE-2022-30525 (Zxyel firewall command injection)
CVE-2022-30525CRITICALunder attack10 May 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
GitHub PoC
lowkey0808/cve-2020-25540
CVE-2020-2554010 May 2022
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISK
open
GitHub PoC6
CVE-2022-1388-PocExp,新增了多线程,F5 BIG-IP RCE exploitation
CVE-2022-1388CRITICALunder attackransomware10 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
vesperp/CVE-2022-1388-F5-BIG-IP
CVE-2022-1388CRITICALunder attackransomware10 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC5
PoC For F5 BIG-IP - bash script Exploit one Liner
CVE-2022-1388CRITICALunder attackransomware10 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
BIG-IP iControl REST vulnerability CVE-2022-1388 PoC
CVE-2022-1388CRITICALunder attackransomware10 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
0xAgun/CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware10 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
CVE-2007-2447
CVE-2007-244710 May 2022
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
previouspage 317 / 463next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.