Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,533 exploits
VulnCheck XDB
initial-access
CVE-2009-1151CRITICALunder attack24 Jun 2023
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-3459823 Jun 2023
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files
50RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-30136CRITICAL23 Jun 2023
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-27997CRITICALunder attackransomware23 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
Exploit-DB
NCH Express Invoice - Clear Text Password Storage and Account Takeover
CVE-2020-11560localwindows23 Jun 2023
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file.
23RISK
open
GitHub PoC10
An exploit for CVE-2018-5955 GitStack 2.3.10 Unauthenticated RCE
CVE-2018-595523 Jun 2023
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RISK
open
GitHub PoC
puckiestyle/cve-2023-27997
CVE-2023-27997CRITICALunder attackransomware23 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC1
Windows Network File System Remote exploit (DoS) PoC
CVE-2022-30136CRITICAL23 Jun 2023
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
imbas007/CVE-2023-27997-Check
CVE-2023-27997CRITICALunder attackransomware22 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-3614422 Jun 2023
An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to downlo
50RISK
open
VulnCheck XDB
infoleak
CVE-2023-27997CRITICALunder attackransomware22 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47075HIGHwebappsaspx22 Jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the
68RISK
open
Exploit-DB
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
CVE-2022-47076HIGHwebappsaspx22 Jun 2023
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via Display
41RISK
open
VulnCheck XDB
initial-access
CVE-2018-11776HIGHunder attack21 Jun 2023
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC34
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
CVE-2022-42475CRITICALunder attackransomware21 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-42475CRITICALunder attackransomware21 Jun 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open
GitHub PoC
sonpt-afk/CVE-2018-11776-FIS
CVE-2018-11776HIGHunder attack21 Jun 2023
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-2868CRITICALunder attack20 Jun 2023
Remote Code injection in Barracuda Email Security Gateway
100RISK
open
GitHub PoC2
Analysis & Exploit
CVE-2023-22809HIGH20 Jun 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
Exploit-DB
Nokia ASIKA 7.13.52 - Hard-coded private key disclosure
CVE-2023-25187MEDIUMremotehardware20 Jun 2023
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
33RISK
open
GitHub PoC1
Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info
CVE-2021-42013CRITICALunder attackransomware20 Jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC2
POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability
CVE-2022-0847HIGHunder attack20 Jun 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Exploit-DBVexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
CVE-2023-27372CRITICALwebappsphp20 Jun 2023
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack20 Jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Exploit-DB
WP Sticky Social 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS)
CVE-2023-3320MEDIUMwebappsphp20 Jun 2023
The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,
33RISK
open
GitHub PoC2
PoC and exploit for CVE-2022-22965 Spring4Shell
CVE-2022-22965CRITICALunder attack20 Jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Exploit-DBVexDay Proof
Super Socializer 7.13.52 - Reflected XSS
CVE-2023-2779MEDIUMwebappsphp20 Jun 2023
Super Socializer < 7.13.52 - Reflected XSS
48RISK
open
VulnCheck XDB
infoleak
CVE-2023-1454MEDIUM20 Jun 2023
jeecg-boot qurestSql sql injection
60RISK
open
GitHub PoC11
cfielding-r7/poc-cve-2023-2868
CVE-2023-2868CRITICALunder attack20 Jun 2023
Remote Code injection in Barracuda Email Security Gateway
100RISK
open
GitHub PoC19
Exploits for a heap overflow in MiniDLNA <=1.3.2 (CVE-2023-33476)
CVE-2023-33476CRITICAL20 Jun 2023
ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by
48RISK
open
previouspage 491 / 2,585next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.