Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
77,620 exploits
GitHub PoC7
CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)
CVE-2022-38181HIGHunder attack13 Apr 2023
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishan
76RISK
open
VulnCheck XDB
infoleak
CVE-2023-28432HIGHunder attack13 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC3
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
CVE-2022-46169CRITICALunder attack13 Apr 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-35250HIGH13 Apr 2023
Directory Transversal Vulnerability in Serv-U 15.3
61RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware12 Apr 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800
CVE-2022-1388CRITICALunder attackransomware12 Apr 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-41800HIGH12 Apr 2023
Appliance mode iControl REST vulnerability
68RISK
open
Metasploit600
ManageEngine ADManager Plus ChangePasswordAction Authenticated Command Injection
CVE-2023-29084HIGH12 Apr 2023
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy setti
58RISK
open
Metasploit300
CVE-2023-21554 - QueueJumper - MSMQ RCE Check
CVE-2023-21554CRITICAL11 Apr 2023
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open
Metasploit400
Windows Common Log File System Driver (clfs.sys) Elevation of Privilege Vulnerability
CVE-2023-28252HIGHunder attackransomware11 Apr 2023
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2023-1454MEDIUM11 Apr 2023
jeecg-boot qurestSql sql injection
60RISK
open
GitHub PoC
FzBacon/CVE-2023-25234_Tenda_AC6_stack_overflow
CVE-2023-25234CRITICAL11 Apr 2023
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInte
53RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack11 Apr 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack11 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0
CVE-2022-46169CRITICALunder attack11 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
nik0nz7/CVE-2020-14882
CVE-2020-14882CRITICALunder attack11 Apr 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
Exploit-DB
Paradox Security Systems IPR512 - Denial Of Service
CVE-2023-24709HIGHdoshardware10 Apr 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISK
open
Exploit-DB
Online Computer and Laptop Store 1.0 - Remote Code Execution (RCE)
CVE-2023-1826MEDIUMwebappsphp10 Apr 2023
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
33RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack10 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
Rust-based exploit for the CVE-2022-22963 vulnerability
CVE-2022-22963CRITICALunder attack10 Apr 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC3
QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)
CVE-2023-30256MEDIUM10 Apr 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informat
48RISK
open
Exploit-DB
Microsoft Edge (Chromium-based) Webview2 1.0.1661.34 - Spoofing
CVE-2023-24892HIGHlocalmultiple10 Apr 2023
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288909 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack09 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
Test environments for CVE-2023-28432, information disclosure in MinIO clusters
CVE-2023-28432HIGHunder attack09 Apr 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC34
Perform With Mass Exploiter In Joomla 4.2.8.
CVE-2023-23752MEDIUMunder attack09 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
Exploit-DB
Altenergy Power Control Software C1.2.5 - OS command injection
CVE-2023-28343webappshardware08 Apr 2023
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open
Exploit-DB
Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2022-43939HIGHunder attackwebappsjsp08 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open
Exploit-DB
Goanywhere Encryption helper 7.1.1 - Remote Code Execution (RCE)
CVE-2023-0669HIGHunder attackransomwarewebappsjava08 Apr 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
Exploit-DB
Suprema BioStar 2 v2.8.16 - SQL Injection
CVE-2023-27167MEDIUMwebappsmultiple08 Apr 2023
Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/abs
33RISK
open
previouspage 510 / 2,588next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.