Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,401 exploits
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack23 Oct 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864623 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC
Python script get image from Hikvision camera with CVE-2017-7921 vulnerability
CVE-2017-7921CRITICALunder attack23 Oct 2023
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC42
CVE-2013-4786 Go exploitation tool
CVE-2013-478623 Oct 2023
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RISK
open
GitHub PoC112
Exploit for CVE-2023-36802 targeting MSKSSRV.SYS driver
CVE-2023-36802HIGHunder attack23 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack22 Oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware22 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC1
haingn/HIK-CVE-2021-36260-Exploit
CVE-2021-36260CRITICALunder attack22 Oct 2023
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC
banyaksepuh/Mass-CVE-2021-3129-Scanner
CVE-2021-3129CRITICALunder attackransomware22 Oct 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC3
haingn/LoHongCam-CVE-2021-33044
CVE-2021-33044CRITICALunder attack22 Oct 2023
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-33044CRITICALunder attack22 Oct 2023
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC
Nielk74/CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware21 Oct 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
ShivamDey/Samba-CVE-2007-2447-Exploit
CVE-2007-244721 Oct 2023
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
ShivamDey/CVE-2021-23017
CVE-2021-2301721 Oct 2023
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISK
open
GitHub PoC3
CVE-2023-5360 Auto Shell Upload WordPress Royal Elementor 1.3.78 Shell Upload
CVE-2023-536021 Oct 2023
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
cve-2023-22515的python利用脚本
CVE-2023-22515CRITICALunder attackransomware21 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware21 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
yTxZx/CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware20 Oct 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC20
Confluence后台rce
CVE-2023-22515CRITICALunder attackransomware20 Oct 2023
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
local
CVE-2023-36802HIGHunder attack20 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
Trinadh465/frameworks_base_AOSP10_r33_CVE-2023-20963
CVE-2023-20963HIGHunder attack20 Oct 2023
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional
71RISK
open
GitHub PoC36
PoC for CVE-2023-36802 Microsoft Kernel Streaming Service Proxy
CVE-2023-36802HIGHunder attack20 Oct 2023
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC3
yTxZx/CVE-2023-28432
CVE-2023-28432HIGHunder attack20 Oct 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
deIndra/CVE-2023-1698
CVE-2023-1698CRITICAL20 Oct 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864620 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC
testing cve-2023-41993-test
CVE-2023-41993HIGHunder attack20 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
GitHub PoC2
WAGO系统远程代码执行漏洞(CVE-2023-1698)
CVE-2023-1698CRITICAL20 Oct 2023
WAGO: WBM Command Injection in multiple products
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack20 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack20 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-28432HIGHunder attack20 Oct 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
previouspage 459 / 2,581next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.