Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,401 exploits
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware21 Dec 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC4
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
CVE-2009-310320 Dec 2023
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack20 Dec 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-2825CRITICAL20 Dec 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
VulnCheck XDB
local
CVE-2022-46689HIGH20 Dec 2023
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288920 Dec 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-27524HIGHunder attack20 Dec 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
client-side
CVE-2023-32235HIGH20 Dec 2023
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-27997CRITICALunder attackransomware20 Dec 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALunder attackransomware20 Dec 2023
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1394220 Dec 2023
Remote Code Execution in Apache Unomi
50RISK
open
VulnCheck XDB
infoleak
CVE-2023-3519CRITICALunder attackransomware20 Dec 2023
Unauthenticated remote code execution
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM20 Dec 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-23488CRITICAL20 Dec 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack20 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware20 Dec 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack20 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
client-side
CVE-2023-24488MEDIUM20 Dec 2023
Cross site scripting
70RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack20 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-33891HIGHunder attack20 Dec 2023
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack20 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
client-side
CVE-2023-23397CRITICALunder attack20 Dec 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack20 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack20 Dec 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-30190HIGHunder attackransomware20 Dec 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2023-2405520 Dec 2023
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,
23RISK
open
VulnCheck XDB
initial-access
CVE-2010-0738MEDIUMunder attackransomware20 Dec 2023
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288920 Dec 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL20 Dec 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware20 Dec 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
previouspage 444 / 2,581next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.