Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,401 exploits
GitHub PoC2
A proof of concept exploiting CVE-2022-26923.
CVE-2022-26923HIGHunder attack28 Nov 2023
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC4
Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)
CVE-2011-252328 Nov 2023
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware27 Nov 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-4966CRITICALunder attackransomware27 Nov 2023
Unauthenticated sensitive information disclosure
100RISK
open
Metasploit300
Control iD iDSecure Authentication Bypass (CVE-2023-6329)
CVE-2023-6329CRITICAL27 Nov 2023
Control iD iDSecure passwordCustom Authentication Bypass
75RISK
open
GitHub PoC
Programm to exploit a range of ip adresses
CVE-2023-4966CRITICALunder attackransomware27 Nov 2023
Unauthenticated sensitive information disclosure
100RISK
open
GitHub PoC
- using python to detect cve-2017-8464 vulnerbilities
CVE-2017-8464HIGHunder attack27 Nov 2023
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RISK
open
GitHub PoC
edsonjt81/CVE-2023-22515-Scan.
CVE-2023-22515CRITICALunder attackransomware26 Nov 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC1
https://github.com/AbelChe/evil_minio/tree/main 打包留存
CVE-2023-28432HIGHunder attack26 Nov 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
elsvital/cve-2022-33891-fix
CVE-2022-33891HIGHunder attack26 Nov 2023
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
GitHub PoC
working exploit for CVE-2019-9053
CVE-2019-905326 Nov 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864625 Nov 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
client-side
CVE-2023-2033HIGHunder attack24 Nov 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC1
Exploit forCVE-2020-29607
CVE-2020-2960724 Nov 2023
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack23 Nov 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC1
Exploit for CVE-2022-46169
CVE-2022-46169CRITICALunder attack23 Nov 2023
Unauthenticated Command Injection
100RISK
open
Metasploit600
WordPress Royal Elementor Addons RCE
CVE-2023-536023 Nov 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-47246CRITICALunder attackransomware22 Nov 2023
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f
100RISK
open
VulnCheck XDB
client-side
CVE-2022-1364HIGHunder attack22 Nov 2023
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RISK
open
GitHub PoC30
PoC for the CVE-2023-49103
CVE-2023-49103CRITICALunder attack22 Nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISK
open
GitHub PoC2
A1Lin/cve-2022-1364
CVE-2022-1364HIGHunder attack22 Nov 2023
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RISK
open
GitHub PoC
exploit for cve-2023-47246 SysAid RCE (shell upload)
CVE-2023-47246CRITICALunder attackransomware22 Nov 2023
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a f
100RISK
open
GitHub PoC
By passing an overly large string when invoking nethack, it is possible to corrupt memory. jnethack and falconseye are also prone to this vulnerability.
CVE-2003-035822 Nov 2023
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allow
23RISK
open
VulnCheck XDB
infoleak
CVE-2023-49103CRITICALunder attack22 Nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISK
open
Metasploit300
ownCloud Phpinfo Reader
CVE-2023-49103CRITICALunder attack21 Nov 2023
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISK
open
GitHub PoC
Firewall rules to mitigate a zero-day vulnerability malware attack (CVE-2022-22965), known as Spring4Shell
CVE-2022-22965CRITICALunder attack21 Nov 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware21 Nov 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Iris288/CVE-2021-43798
CVE-2021-43798HIGHunder attack21 Nov 2023
Grafana path traversal
100RISK
open
GitHub PoC
Log4Shell (CVE-2021-44228) minecraft demo. Used for education fairs
CVE-2021-44228CRITICALunder attackransomware21 Nov 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack21 Nov 2023
Grafana path traversal
100RISK
open
previouspage 450 / 2,581next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.