Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
VulnCheck XDB
initial-access
CVE-2023-29357CRITICALunder attackransomware30 Sep 2023
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC6
Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129
CVE-2023-4863HIGHunder attack30 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
VulnCheck XDB
initial-access
CVE-2021-34621CRITICAL30 Sep 2023
ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
75RISK
open
VulnCheck XDB
initial-access
CVE-2021-2449929 Sep 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
GitHub PoC
go CVE-2023-24538 patch issue resolver - Kirkstone
CVE-2023-24538CRITICAL29 Sep 2023
Backticks not treated as string delimiters in html/template
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware29 Sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
go CVE-2023-24538 patch issue resolver - Dunfell
CVE-2023-24538CRITICAL29 Sep 2023
Backticks not treated as string delimiters in html/template
48RISK
open
GitHub PoC45
JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit
CVE-2023-42793CRITICALunder attackransomware29 Sep 2023
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALunder attack29 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC
jytmX/CVE-2021-24499
CVE-2021-2449929 Sep 2023
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
GitHub PoC3
CVE-2023-36845 - Juniper Firewall Remote code execution (RCE)
CVE-2023-36845CRITICALunder attack29 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC5
Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129
CVE-2023-4863HIGHunder attack29 Sep 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
VulnCheck XDB
infoleak
CVE-2022-138628 Sep 2023
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RISK
open
GitHub PoC3
PoC for Stored XSS (CVE-2023-43770) Vulnerability
CVE-2023-43770MEDIUMunder attack28 Sep 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISK
open
VulnCheck XDB
client-side
CVE-2023-36884HIGHunder attackransomware28 Sep 2023
Windows Search Remote Code Execution Vulnerability
93RISK
open
VulnCheck XDB
infoleak
CVE-2023-43261HIGH28 Sep 2023
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensiti
68RISK
open
GitHub PoC41
MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit
CVE-2023-36884HIGHunder attackransomware28 Sep 2023
Windows Search Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
sherlocksecurity/CVE-2023-4762-Code-Review
CVE-2023-4762HIGHunder attack27 Sep 2023
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a
83RISK
open
GitHub PoC1
halencarjunior/CVE-2023-36845
CVE-2023-36845CRITICALunder attack27 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC24
buptsb/CVE-2023-4762
CVE-2023-4762HIGHunder attack27 Sep 2023
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a
83RISK
open
VulnCheck XDB
client-side
CVE-2023-4762HIGHunder attack27 Sep 2023
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a
83RISK
open
VulnCheck XDB
infoleak
CVE-2023-36845CRITICALunder attack27 Sep 2023
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
Metasploit600
Kafka UI Unauthenticated Remote Command Execution via the Groovy Filter option.
CVE-2023-52251HIGH27 Sep 2023
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the
78RISK
open
VulnCheck XDB
client-side
CVE-2023-43770MEDIUMunder attack27 Sep 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISK
open
GitHub PoC34
A Proof-Of-Concept for the CVE-2023-43770 vulnerability.
CVE-2023-43770MEDIUMunder attack27 Sep 2023
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISK
open
GitHub PoC9
CVE-2023-34152
CVE-2023-34152CRITICAL27 Sep 2023
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
48RISK
open
Metasploit600
Progress Software WS_FTP Unauthenticated Remote Code Execution
CVE-2023-40044CRITICALunder attackransomware27 Sep 2023
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RISK
open
GitHub PoC1
Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4047 - Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
CVE-2022-4047CRITICAL26 Sep 2023
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48RISK
open
VulnCheck XDB
local
CVE-2022-21894MEDIUM26 Sep 2023
Secure Boot Security Feature Bypass Vulnerability
33RISK
open
GitHub PoC1
New exploitation of 2020 Sophos vuln
CVE-2022-1040CRITICALunder attack26 Sep 2023
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
previouspage 466 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.