Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
Metasploit600
LG Simple Editor Command Injection (CVE-2023-40504)
CVE-2023-40504CRITICAL04 Aug 2023
LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
65RISK
open
VulnCheck XDB
initial-access
CVE-2023-35082CRITICALunder attackransomware04 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISK
open
Exploit-DB
WordPress Plugin Ninja Forms 3.6.25 - Reflected XSS
CVE-2023-37979HIGHwebappsphp04 Aug 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISK
open
GitHub PoC4
Remote Unauthenticated API Access Vulnerability in MobileIron Core 11.2 and older
CVE-2023-35082CRITICALunder attackransomware04 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted fu
100RISK
open
Exploit-DB
Shelly PRO 4PM v0.11.0 - Authentication Bypass
CVE-2023-33383remotehardware04 Aug 2023
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RISK
open
Exploit-DB
PHPJabbers Service Booking Script 1.0 - Reflected XSS
CVE-2023-4113MEDIUMwebappsphp04 Aug 2023
PHP Jabbers Service Booking Script index.php cross site scripting
48RISK
open
Exploit-DB
PHPJabbers Cleaning Business 1.0 - Reflected XSS
CVE-2023-4115MEDIUMwebappsphp04 Aug 2023
PHP Jabbers Cleaning Business index.php cross site scripting
48RISK
open
GitHub PoC
# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor Homepage: https://github.com/pluck-cms/pluck # Version: 4.7.16 # Tested on Ubuntu 20.04.3 LTS # CVE: CVE-2022-26965
CVE-2022-2696504 Aug 2023
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RISK
open
Exploit-DB
PHPJabbers Rental Property Booking 2.0 - Reflected XSS
CVE-2023-4117MEDIUMwebappsphp04 Aug 2023
PHP Jabbers Rental Property Booking index.php cross site scripting
33RISK
open
Exploit-DB
PHPJabbers Night Club Booking 1.0 - Reflected XSS
CVE-2023-4114MEDIUMwebappsphp04 Aug 2023
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RISK
open
GitHub PoC
Vulnerable environment of CVE-2013-2251 (S2-016) for testing
CVE-2013-2251CRITICALunder attack04 Aug 2023
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RISK
open
Exploit-DB
PHPJabbers Taxi Booking 2.0 - Reflected XSS
CVE-2023-4116MEDIUMwebappsphp04 Aug 2023
PHP Jabbers Taxi Booking index.php cross site scripting
48RISK
open
GitHub PoC
Vulnerable environment of CVE-2020-17530 (S2-061) for testing
CVE-2020-17530CRITICALunder attack04 Aug 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Post Access via IDOR
CVE-2023-3219webappsphp04 Aug 2023
EventON < 2.1.2 - Unauthenticated Post Access via IDOR
38RISK
open
Exploit-DB
Wordpress Plugin EventON Calendar 4.4 - Unauthenticated Event Access
CVE-2023-2796webappsphp04 Aug 2023
EventON < 2.1.2 - Unauthenticated Event Access
50RISK
open
Exploit-DB
PHPJabbers Shuttle Booking Software 1.0 - Reflected XSS
CVE-2023-4112MEDIUMwebappsphp04 Aug 2023
PHP Jabbers Shuttle Booking Software index.php cross site scripting
48RISK
open
GitHub PoC2
CVE-2023-37979 PoC and Checker
CVE-2023-37979HIGH04 Aug 2023
WordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
56RISK
open
Exploit-DB
Academy LMS 6.0 - Reflected XSS
CVE-2023-4119MEDIUMwebappsphp04 Aug 2023
Academy LMS courses cross site scripting
33RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864603 Aug 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC64
mistymntncop/CVE-2023-2033
CVE-2023-2033HIGHunder attack02 Aug 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
GitHub PoC
726232111/CVE-2023-28252
CVE-2023-28252HIGHunder attackransomware02 Aug 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
overgrowncarrot1/DejaVu-CVE-2021-22205
CVE-2021-22205CRITICALunder attackransomware02 Aug 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864602 Aug 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC1
CVE-2020-0688 modified exploit for Exchange 2010
CVE-2020-0688HIGHunder attackransomware02 Aug 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC1
asepsaepdin/CVE-2010-1240
CVE-2010-124002 Aug 2023
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware02 Aug 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware02 Aug 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC4
Exploit CVE-2021-41773 and CVE-2021-42013
CVE-2021-41773HIGHunder attackransomware02 Aug 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
client-side
CVE-2023-2033HIGHunder attack02 Aug 2023
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corr
83RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware02 Aug 2023
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
previouspage 479 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.