Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
77,620 exploits
Metasploit600
Ivanti Avalanche FileStoreConfig File Upload
CVE-2023-28128HIGH24 Apr 2023
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could
58RISK
open
GitHub PoC
andyhsu024/CVE-2021-29447
CVE-2021-29447HIGH24 Apr 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
Metasploit600
invscout RPM Privilege Escalation
CVE-2023-28528HIGH24 Apr 2023
IBM AIX command execution
36RISK
open
GitHub PoC13
CVE-2023-22894
CVE-2023-22894CRITICAL24 Apr 2023
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RISK
open
GitHub PoC16
CVE-2023-1671-POC, based on dnslog platform
CVE-2023-1671CRITICALunder attack24 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
GitHub PoC1
RubXkuB/PoC-Metabase-CVE-2021-41277
CVE-2021-41277CRITICALunder attack24 Apr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISK
open
GitHub PoC3
Pre-Auth RCE in Sophos Web Appliance
CVE-2023-1671CRITICALunder attack23 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-40799HIGHunder attack23 Apr 2023
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l
83RISK
open
GitHub PoC1
glen-pearson/ProxyLogon-CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware23 Apr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALunder attackransomware23 Apr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALunder attack23 Apr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware22 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1609CRITICAL22 Apr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open
GitHub PoC1
Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.
CVE-2022-1609CRITICAL22 Apr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open
GitHub PoC55
Proof of Concept Exploit for PaperCut CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware22 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC2
「💥」CVE-2022-4944: KodExplorer <= 4.49 - CSRF to Arbitrary File Upload
CVE-2022-4944MEDIUM21 Apr 2023
kalcaddle KodExplorer cross-site request forgery
33RISK
open
GitHub PoC12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
Anonimo501/ssh_enum_users_CVE-2018-15473
CVE-2018-15473MEDIUM21 Apr 2023
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-1454MEDIUM21 Apr 2023
jeecg-boot qurestSql sql injection
60RISK
open
Metasploit300
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
CVE-2023-26876HIGH21 Apr 2023
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
36RISK
open
GitHub PoC5
A simple python script to check if a service is vulnerable
CVE-2023-27350CRITICALunder attackransomware21 Apr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Exploit-DB
Linux Kernel 6.2 - Userspace Processes To Enable Mitigation
CVE-2023-1998MEDIUMlocallinux20 Apr 2023
Spectre v2 SMT mitigations problem in Linux kernel
33RISK
open
Exploit-DB
Microsoft Word 16.72.23040900 - Remote Code Execution (RCE)
CVE-2023-28311HIGHremotemultiple20 Apr 2023
Microsoft Word Remote Code Execution Vulnerability
41RISK
open
Exploit-DBVexDay Proof
Bang Resto v1.0 - 'Multiple' SQL Injection
CVE-2023-29849HIGHwebappsphp20 Apr 2023
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice
41RISK
open
VulnCheck XDB
initial-access
CVE-2020-1745320 Apr 2023
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter.
43RISK
open
Exploit-DBVexDay Proof
Bang Resto v1.0 - Stored Cross-Site Scripting (XSS)
CVE-2023-29848MEDIUMwebappsphp20 Apr 2023
Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in
33RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH20 Apr 2023
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware20 Apr 2023
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 508 / 2,588next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.