Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
13,885 exploits
GitHub PoC93
CVE-2022-1388 F5 BIG-IP RCE 批量检测
CVE-2022-1388CRITICALunder attackransomware07 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
jr64/CVE-2015-0311
CVE-2015-0311HIGHunder attack07 May 2022
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RISK
open
GitHub PoC2
fuzzing with libFuzzer,inlude openssl heartbleed (CVE-2014-0160)
CVE-2014-0160HIGHunder attack07 May 2022
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Satheesh575555/external_expat_AOSP10_r33_CVE-2022-25236
CVE-2022-25236CRITICAL06 May 2022
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace
60RISK
open
GitHub PoC28
This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
CVE-2022-1388CRITICALunder attackransomware06 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC16
may the poc with you
CVE-2022-1040CRITICALunder attack06 May 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC6
WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
CVE-2022-044106 May 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open
GitHub PoC53
K23605346: BIG-IP iControl REST vulnerability CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware05 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC25
Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)
CVE-2022-1388CRITICALunder attackransomware05 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
1
CVE-2022-29464CRITICALunder attackransomware05 May 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC
CVE-2022-22954 analyst
CVE-2022-22954CRITICALunder attackransomware05 May 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC13
PoC of CVE-2022-24707
CVE-2022-24707HIGH03 May 2022
SQL injection in anuko timetracker
41RISK
open
GitHub PoC
CVE-2018-17553 PoC
CVE-2018-1755303 May 2022
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RISK
open
GitHub PoC12
Exploit for CVE-2021-3560 (Polkit) - Local Privilege Escalation
CVE-2021-3560HIGHunder attack02 May 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC
Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware02 May 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC60
yuanLink/CVE-2022-26809
CVE-2022-26809CRITICAL01 May 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
CVE-2021-44228 Log4j Summary
CVE-2021-44228CRITICALunder attackransomware30 Apr 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC25
PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)
CVE-2021-3560HIGHunder attack30 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC8
This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.
CVE-2018-1942229 Apr 2022
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISK
open
GitHub PoC
Enokiy/spring-RCE-CVE-2022-22965
CVE-2022-22965CRITICALunder attack29 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC116
PolicyKit CVE-2021-3560 Exploit (Authentication Agent)
CVE-2021-3560HIGHunder attack29 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC2
CVE-2022-29464 POC exploit
CVE-2022-29464CRITICALunder attackransomware29 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC13
A tool for extracting, modifying, and crafting ASDM binary packages (CVE-2022-20829)
CVE-2022-20829CRITICAL28 Apr 2022
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
48RISK
open
GitHub PoC
RedLeavesChilde/CVE-2021-40444
CVE-2021-40444HIGHunder attackransomware28 Apr 2022
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
for kernel 3.18.x
CVE-2019-2215HIGHunder attack28 Apr 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC14
CVE-2021-41773&CVE-2021-42013图形化漏洞检测利用工具
CVE-2021-41773HIGHunder attackransomware27 Apr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC4
khidottrivi/CVE-2022-22965
CVE-2022-22965CRITICALunder attack27 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
OS X 10.11.6 LPE PoC for CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMunder attack27 Apr 2022
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISK
open
GitHub PoC
lowkey0808/cve-2022-29464
CVE-2022-29464CRITICALunder attackransomware26 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC1
Exploit for CVE-2021-3036, HTTP Smuggling + buffer overflow in PanOS 8.x
CVE-2021-3064CRITICAL26 Apr 2022
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
53RISK
open
previouspage 319 / 463next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.