Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
77,533 exploits
Metasploit300
GitLab Authenticated File Read
CVE-2023-2825CRITICAL23 May 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
Metasploit600
Apache RocketMQ update config RCE
CVE-2023-33246CRITICALunder attack23 May 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
Exploit-DBVexDay Proof
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
CVE-2022-41544HIGHwebappsphp23 May 2023
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-32243CRITICAL23 May 2023
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RISK
open
Exploit-DB
FusionInvoice 2023-1.0 - Stored XSS (Cross-Site Scripting)
CVE-2023-25439MEDIUMwebappsmultiple23 May 2023
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr
33RISK
open
Exploit-DB
ChurchCRM v4.5.4 - Reflected XSS via Image (Authenticated)
CVE-2023-31699MEDIUMwebappsphp23 May 2023
ChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file.
33RISK
open
Exploit-DB
PnPSCADA v2.x - Unauthenticated PostgreSQL Injection
CVE-2023-1934CRITICALwebappshardware23 May 2023
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL
48RISK
open
GitHub PoC30
PoC for CVE-2023-28771 based on Rapid7's excellent writeup
CVE-2023-28771CRITICALunder attack23 May 2023
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISK
open
Exploit-DB
Webkul Qloapps 1.5.2 - Cross-Site Scripting (XSS)
CVE-2023-30256MEDIUMwebappsphp23 May 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISK
open
Exploit-DB
PaperCut NG/MG 22.0.4 - Remote Code Execution (RCE)
CVE-2023-27350CRITICALunder attackransomwarewebappsmultiple23 May 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH23 May 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
Exploit-DB
CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)
CVE-2023-25440MEDIUMwebappsphp23 May 2023
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to exe
33RISK
open
VulnCheck XDB
initial-access
CVE-2019-1949223 May 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISK
open
Exploit-DB
Yank Note v3.52.1 (Electron) - Arbitrary Code Execution
CVE-2023-31874HIGHlocalmultiple23 May 2023
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro
41RISK
open
Exploit-DBVexDay Proof
Bludit CMS v3.14.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
CVE-2023-31698webappsphp23 May 2023
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's securit
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-1949223 May 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISK
open
Exploit-DB
Apache Superset 2.0.0 - Authentication Bypass
CVE-2023-27524HIGHunder attackwebappsmultiple23 May 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1949223 May 2023
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RISK
open
GitHub PoC
This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).
CVE-2014-1812HIGHunder attackransomware22 May 2023
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RISK
open
VulnCheck XDB
initial-access
CVE-2023-25690CRITICAL22 May 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
GitHub PoC286
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL22 May 2023
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
GitHub PoC1
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
CVE-2007-596222 May 2023
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RISK
open
GitHub PoC
Dockerized POC for CVE-2022-42889 Text4Shell
CVE-2022-4288922 May 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288922 May 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH22 May 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
GitHub PoC
RCE Unauth in PyLoad <0.5.0b3.dev31
CVE-2023-0297CRITICAL21 May 2023
Code Injection in pyload/pyload
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack21 May 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack21 May 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL21 May 2023
Code Injection in pyload/pyload
85RISK
open
GitHub PoC
antisecc/CVE-2022-46169
CVE-2022-46169CRITICALunder attack21 May 2023
Unauthenticated Command Injection
100RISK
open
previouspage 499 / 2,585next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.