Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,401 exploits
GitHub PoC1
CVE-2023-38831 Proof-of-concept code
CVE-2023-38831HIGHunder attackransomware12 Dec 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
RCE for Webmin CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware12 Dec 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC9
CVE-2021-40438 Apache <= 2.4.48 SSRF exploit
CVE-2021-40438CRITICALunder attackransomware12 Dec 2023
mod_proxy SSRF
100RISK
open
GitHub PoC
sigridou/CVE-2023-44487-
CVE-2023-44487HIGHunder attack11 Dec 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC
hadrian3689/CVE-2023-23752_Joomla
CVE-2023-23752MEDIUMunder attack11 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack11 Dec 2023
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack11 Dec 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack11 Dec 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack11 Dec 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
Metasploit600
WordPress Backup Migration Plugin PHP Filter Chain RCE
CVE-2023-6553CRITICAL11 Dec 2023
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
GitHub PoC2
Cisco CVE-2023-20198
CVE-2023-20198CRITICALunder attack11 Dec 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
client-side
CVE-2020-0674HIGHunder attack10 Dec 2023
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
GitHub PoC
qailanet/cve-2022-41352-zimbra-rce
CVE-2022-41352CRITICALunder attack10 Dec 2023
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISK
open
GitHub PoC46
PoC Exploit for VM2 Sandbox Escape Vulnerability
CVE-2023-30547CRITICAL10 Dec 2023
Sandbox Escape in vm2
70RISK
open
GitHub PoC
PoC of CVE-2023-4911
CVE-2023-4911HIGHunder attack10 Dec 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
VulnCheck XDB
local
CVE-2023-4911HIGHunder attack10 Dec 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
Metasploit600
GL.iNet Unauthenticated Remote Command Execution via the logread module.
CVE-2023-50445HIGH10 Dec 2023
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000
36RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864610 Dec 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC
Porting the CVE-2020-0674 exploit for Windows8.1 and Windows10
CVE-2020-0674HIGHunder attack10 Dec 2023
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RISK
open
Metasploit600
GL.iNet Unauthenticated Remote Command Execution via the logread module.
CVE-2023-50919CRITICAL10 Dec 2023
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string
75RISK
open
VulnCheck XDB
local
CVE-2023-36874HIGHunder attack09 Dec 2023
Windows Error Reporting Service Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC2
Exploit for CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware09 Dec 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC14
CVE-2023-20273 Exploit PoC
CVE-2023-20273HIGHunder attack09 Dec 2023
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RISK
open
GitHub PoC1
Vulnerability in HTTP Protocol Stack Enabling Remote Code Execution and Potential System Crash.
CVE-2022-21907CRITICAL09 Dec 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL09 Dec 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-20273HIGHunder attack09 Dec 2023
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware09 Dec 2023
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.
CVE-2023-4966CRITICALunder attackransomware08 Dec 2023
Unauthenticated sensitive information disclosure
100RISK
open
GitHub PoC27
An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all non-administator passwords, private keys and High Availability passwords.
CVE-2019-6693MEDIUMunder attackransomware08 Dec 2023
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
VulnCheck XDB
local
CVE-2019-6693MEDIUMunder attackransomware08 Dec 2023
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
previouspage 447 / 2,581next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.