Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,533 exploits
GitHub PoC
MrDottt/CVE-2021-22911
CVE-2021-2291105 Jun 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
Exploit-DB
File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution (RCE)
CVE-2023-2068webappsphp04 Jun 2023
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RISK
open
Exploit-DB
STARFACE 7.3.0.10 - Authentication with Password Hash Possible
CVE-2023-33243HIGHwebappsjsp04 Jun 2023
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the
41RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH04 Jun 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
GitHub PoC3
Poc&Exp,支持批量扫描,反弹shell
CVE-2022-22965CRITICALunder attack03 Jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Exploit created in python3 to exploit known vulnerabilities in Apache web server (CVE-2021-41773, CVE-2021-42013)
CVE-2021-41773HIGHunder attackransomware03 Jun 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware03 Jun 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack03 Jun 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware03 Jun 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-044102 Jun 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open
GitHub PoC1
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
CVE-2022-044102 Jun 2023
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RISK
open
GitHub PoC3
CVE-2023-33246:Apache RocketMQ 远程命令执行漏洞检测工具
CVE-2023-33246CRITICALunder attack02 Jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC81
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALunder attack01 Jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC114
Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit
CVE-2023-33246CRITICALunder attack01 Jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC
[CVE-2021-33690] Server Side Request Forgery vulnerability in SAP NetWeaver Development Infrastructure
CVE-2021-33690CRITICAL01 Jun 2023
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RISK
open
Metasploit600
Chamilo unauthenticated command injection in PowerPoint upload
CVE-2023-3496001 Jun 2023
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to ex
60RISK
open
Metasploit600
Splunk "edit_user" Capability Privilege Escalation
CVE-2023-32707HIGH01 Jun 2023
‘edit_user’ Capability Privilege Escalation
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALunder attack01 Jun 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-33690CRITICAL01 Jun 2023
Server-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Compo
75RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack31 May 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC2
A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability
CVE-2022-22965CRITICALunder attack31 May 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Exploit-DB
Flexense HTTP Server 10.6.24 - Buffer Overflow (DoS) (Metasploit)
CVE-2018-8065remotemultiple31 May 2023
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RISK
open
GitHub PoC2
4mazing/CVE-2023-33246-Copy
CVE-2023-33246CRITICALunder attack31 May 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
Exploit-DB
Pydio Cells 4.1.2 - Cross-Site Scripting (XSS) via File Download
CVE-2023-32751MEDIUMwebappsgo31 May 2023
Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are genera
33RISK
open
Exploit-DB
unilogies/bumsys v1.0.3 beta - Unrestricted File Upload
CVE-2023-0455HIGHwebappsphp31 May 2023
Unrestricted Upload of File with Dangerous Type in unilogies/bumsys
41RISK
open
Exploit-DB
Pydio Cells 4.1.2 - Unauthorised Role Assignments
CVE-2023-32749HIGHwebappsgo31 May 2023
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RISK
open
Metasploit600
MOVEit SQL Injection vulnerability
CVE-2023-34362CRITICALunder attackransomware31 May 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
Metasploit600
Wordpress File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution through shortcode
CVE-2023-206831 May 2023
File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
50RISK
open
Exploit-DBVexDay Proof
Online Security Guards Hiring System 1.0 - Reflected XSS
CVE-2023-0527LOWwebappsphp31 May 2023
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RISK
open
GitHub PoC1
Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.
CVE-2010-207531 May 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open
previouspage 496 / 2,585next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.