Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
77,620 exploits
Exploit-DB
ERPNext 12.29 - Cross-Site Scripting (XSS)
CVE-2022-28598webappsjava05 Apr 2023
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-contro
23RISK
open
Exploit-DB
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
CVE-2020-5330HIGHremotehardware05 Apr 2023
Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22
46RISK
open
GitHub PoC7
Poc for CVE-2023-23752
CVE-2023-23752MEDIUMunder attack04 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC3
brosck/CVE-2006-3392
CVE-2006-339204 Apr 2023
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288904 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack04 Apr 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
docker for CVE-2022-42889
CVE-2022-4288904 Apr 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack04 Apr 2023
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-43769HIGHunder attack04 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open
GitHub PoC2
CVE-2014-6287
CVE-2014-6287CRITICALunder attack04 Apr 2023
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-43939HIGHunder attack04 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open
Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVE-2022-43769HIGHunder attack04 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
100RISK
open
Metasploit600
Pentaho Business Server Auth Bypass and Server Side Template Injection RCE
CVE-2022-43939HIGHunder attack04 Apr 2023
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
100RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
CVE-2023-23161webappsphp03 Apr 2023
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
CVE-2023-23162webappsphp03 Apr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack03 Apr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
Exploit-DBVexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
CVE-2023-23163webappsphp03 Apr 2023
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
23RISK
open
Exploit-DB
Windows 11 10.0.22000 - Backup service Privilege Escalation
CVE-2023-21752HIGHlocalwindows03 Apr 2023
Windows Backup Service Elevation of Privilege Vulnerability
41RISK
open
Exploit-DB
Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
CVE-2023-0084HIGHwebappsphp03 Apr 2023
Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting
46RISK
open
GitHub PoC2
my python poc CVE-2023-24774 and CVE-2023-24775 this sqli cve funadmin
CVE-2023-24775CRITICAL03 Apr 2023
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member
53RISK
open
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
CVE-2022-31126CRITICALwebappspython03 Apr 2023
Unauthenticated Remote Code Execution in Roxy-wi
75RISK
open
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
CVE-2022-31125CRITICALwebappspython03 Apr 2023
Authentication Bypass in Roxy-wi
53RISK
open
Exploit-DB
Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload
CVE-2022-31161CRITICALwebappspython03 Apr 2023
Roxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Upload
68RISK
open
Exploit-DB
sudo 1.8.0 to 1.9.12p1 - Privilege Escalation
CVE-2023-22809HIGHlocallinux03 Apr 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
Exploit-DBVexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
CVE-2020-25213CRITICALunder attackwebappsphp03 Apr 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
Exploit-DB
GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin
CVE-2022-34127HIGHwebappsphp03 Apr 2023
The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.p
41RISK
open
Exploit-DBVexDay Proof
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
CVE-2023-23488CRITICALwebappsphp03 Apr 2023
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RISK
open
Exploit-DB
Nacos 2.0.3 - Access Control vulnerability
CVE-2021-43116webappsjava03 Apr 2023
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on l
23RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack03 Apr 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
Exploit-DB
GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)
CVE-2022-34128CRITICALwebappsphp03 Apr 2023
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data
48RISK
open
previouspage 514 / 2,588next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.