Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,444 exploits
GitHub PoC1
emomeni/Simple-Ansible-for-CVE-2023-20198
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC1
cisco-CVE-2023-20198-tester
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC20
CVE-2023-20198 Checkscript
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC33
CVE-2023-20198 & 0Day Implant Scanner
CVE-2023-20198CRITICALunder attack17 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC
Proxyshell for Exploiting CVE-2021-34473
CVE-2021-34473CRITICALunder attackransomware17 Oct 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864617 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
local
CVE-2023-4911HIGHunder attack17 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware17 Oct 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHunder attack17 Oct 2023
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC80
检测域内常见一把梭漏洞,包括:NoPac、ZeroLogon、CVE-2022-26923、PrintNightMare
CVE-2022-26923HIGHunder attack17 Oct 2023
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC43
Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.
CVE-2023-4911HIGHunder attack17 Oct 2023
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC22
A python based exploit to test out rapid reset attack (CVE-2023-44487)
CVE-2023-44487HIGHunder attack16 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
Metasploit300
Cisco IOX XE unauthenticated OS command execution
CVE-2023-20273HIGHunder attack16 Oct 2023
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RISK
open
Metasploit600
Cisco IOX XE Unauthenticated RCE Chain
CVE-2023-20198CRITICALunder attack16 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
Metasploit600
Cisco IOX XE Unauthenticated RCE Chain
CVE-2023-20273HIGHunder attack16 Oct 2023
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject c
100RISK
open
Metasploit300
Cisco IOX XE unauthenticated Command Line Interface (CLI) execution
CVE-2023-20198CRITICALunder attack16 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
Metasploit300
Cisco IOX XE unauthenticated OS command execution
CVE-2023-20198CRITICALunder attack16 Oct 2023
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC5
CVE-2023-41993
CVE-2023-41993HIGHunder attack16 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
GitHub PoC16
testing poc
CVE-2023-41993HIGHunder attack16 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
VulnCheck XDB
client-side
CVE-2023-41993HIGHunder attack16 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
VulnCheck XDB
client-side
CVE-2023-41993HIGHunder attack16 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack16 Oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC1
This repository has the sole purpose of rewriting the CVE-2019-9053 script, which in the original publication is written in Python 2.7. I will be using Python 3.
CVE-2019-905316 Oct 2023
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252316 Oct 2023
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC202
po6ix/POC-for-CVE-2023-41993
CVE-2023-41993HIGHunder attack15 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
VulnCheck XDB
client-side
CVE-2023-41993HIGHunder attack15 Oct 2023
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to
76RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack15 Oct 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack15 Oct 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864615 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864614 Oct 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
previouspage 461 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.