Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
77,449 exploits
GitHub PoC117
CVE-2023-35078 Remote Unauthenticated API Access Vulnerability Exploit POC
CVE-2023-35078CRITICALunder attackransomware29 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC5
Proof of concept script to check if the site is vulnerable to CVE-2023-35078
CVE-2023-35078CRITICALunder attackransomware29 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC
Pseudo shell for CVE-2013-0156.
CVE-2013-015629 Jul 2023
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
VulnCheck XDB
initial-access
CVE-2013-015629 Jul 2023
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL29 Jul 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
VulnCheck XDB
infoleak
CVE-2023-35078CRITICALunder attackransomware29 Jul 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC9
CVE-2023-22884 PoC
CVE-2023-22884CRITICAL29 Jul 2023
Apache Airflow, Apache Airflow MySQL Provider: Arbitrary file read via MySQL provider in Apache Airflow
53RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864629 Jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
Exploit-DBVexDay Proof
WordPress Plugin AN_Gradebook 5.0.1 - SQLi
CVE-2023-2636webappsphp28 Jul 2023
AN_GradeBook <= 5.0.1 - Subscriber+ SQLi
23RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware28 Jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3846LOWwebappsphp28 Jul 2023
mooSocial mooDating URL pages cross site scripting
43RISK
open
Exploit-DB
Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 - Password Dumping
CVE-2023-36266localmultiple28 Jul 2023
An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Brows
23RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864628 Jul 2023
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
Exploit-DBVexDay Proof
RosarioSIS 10.8.4 - CSV Injection
CVE-2023-29918MEDIUMwebappsphp28 Jul 2023
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
33RISK
open
GitHub PoC17
Voyag3r-Security/CVE-2023-1389
CVE-2023-1389HIGHunder attack28 Jul 2023
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISK
open
GitHub PoC
JohnGilbert57/CVE-2021-4034-Capture-the-flag
CVE-2021-4034HIGHunder attackransomware28 Jul 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC2
ridsoliveira/Fix-CVE-2023-36884
CVE-2023-36884HIGHunder attackransomware28 Jul 2023
Windows Search Remote Code Execution Vulnerability
93RISK
open
Exploit-DBVexDay Proof
copyparty v1.8.6 - Reflected Cross Site Scripting (XSS)
CVE-2023-38501MEDIUMwebappspython28 Jul 2023
copyparty vulnerable to reflected cross-site scripting via k304 parameter
48RISK
open
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3848LOWwebappsphp28 Jul 2023
mooSocial mooDating URL view cross site scripting
43RISK
open
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3844LOWwebappsphp28 Jul 2023
mooSocial mooDating URL friends cross site scripting
43RISK
open
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3849LOWwebappsphp28 Jul 2023
mooSocial mooDating URL find-a-match cross site scripting
43RISK
open
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3845LOWwebappsphp28 Jul 2023
mooSocial mooDating URL ajax_invite cross site scripting
43RISK
open
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3847LOWwebappsphp28 Jul 2023
mooSocial mooDating URL users cross site scripting
43RISK
open
Exploit-DB
mooDating 1.2 - Reflected Cross-site scripting (XSS)
CVE-2023-3843LOWwebappsphp28 Jul 2023
mooSocial mooDating URL question cross site scripting
43RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware27 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC1
Exploit for the vulnerability of Ultimate Member Plugin.
CVE-2023-346027 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-346027 Jul 2023
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALunder attackransomware27 Jul 2023
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
GitHub PoC2
CVE-2021-3129 | Laravel Debug Mode Vulnerability
CVE-2021-3129CRITICALunder attackransomware27 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
Laravel RCE (CVE-2021-3129)
CVE-2021-3129CRITICALunder attackransomware26 Jul 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
previouspage 481 / 2,582next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.