Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
77,620 exploits
Exploit-DBVexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
CVE-2022-31125CRITICALwebappspython03 Apr 2023
Authentication Bypass in Roxy-wi
53RISK
open
Exploit-DB
GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin
CVE-2022-34127HIGHwebappsphp03 Apr 2023
The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.p
41RISK
open
Exploit-DB
Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload
CVE-2022-31161CRITICALwebappspython03 Apr 2023
Roxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Upload
68RISK
open
Exploit-DBVexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
CVE-2020-25213CRITICALunder attackwebappsphp03 Apr 2023
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
GitHub PoC2
my python poc CVE-2023-24774 and CVE-2023-24775 this sqli cve funadmin
CVE-2023-24775CRITICAL03 Apr 2023
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member
53RISK
open
Exploit-DB
Metform Elementor Contact Form Builder v3.1.2 - Unauthenticated Stored Cross-Site Scripting (XSS)
CVE-2023-0084HIGHwebappsphp03 Apr 2023
Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting
46RISK
open
GitHub PoC
Struts2 S2-061 远程命令执行漏洞(CVE-2020-17530)
CVE-2020-17530CRITICALunder attack02 Apr 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALunder attack02 Apr 2023
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC1
A vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105
CVE-2021-44228CRITICALunder attackransomware02 Apr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DBVexDay Proof
GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-2884CRITICALwebappsruby01 Apr 2023
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RISK
open
Exploit-DBVexDay Proof
Apache 2.4.x - Buffer Overflow
CVE-2021-44790webappsmultiple01 Apr 2023
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISK
open
Exploit-DB
perfSONAR v4.4.5 - Partial Blind CSRF
CVE-2022-41413MEDIUMwebappsmultiple01 Apr 2023
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attack
33RISK
open
GitHub PoC8
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
CVE-2022-3552HIGH01 Apr 2023
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISK
open
GitHub PoC1
WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2022-46169). Run it at your own risk!
CVE-2022-46169CRITICALunder attack01 Apr 2023
Unauthenticated Command Injection
100RISK
open
Exploit-DB
Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)
CVE-2022-30519MEDIUMwebappswindows01 Apr 2023
XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary c
33RISK
open
GitHub PoC
lionelmusonza/CVE-2023-26866
CVE-2023-26866CRITICAL01 Apr 2023
GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respe
48RISK
open
Exploit-DB
Nexxt Router Firmware 42.103.1.5095 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-44149HIGHremotehardware01 Apr 2023
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
53RISK
open
Exploit-DB
Enlightenment v0.25.3 - Privilege escalation
CVE-2022-37706HIGHlocallinux01 Apr 2023
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open
VulnCheck XDB
initial-access
CVE-2021-2291101 Apr 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
Exploit-DB
AD Manager Plus 7122 - Remote Code Execution (RCE)
CVE-2021-44228CRITICALunder attackransomwareremotejava01 Apr 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)
CVE-2022-44877CRITICALunder attackwebappslinux01 Apr 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
Exploit-DB
TP-Link TL-WR902AC firmware 210730 (V3) - Remote Code Execution (RCE) (Authenticated)
CVE-2022-48194HIGHremotehardware01 Apr 2023
TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a De
53RISK
open
Exploit-DBVexDay Proof
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
CVE-2022-48197webappsphp01 Apr 2023
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RISK
open
GitHub PoC
devAL3X/CVE-2022-46169_poc
CVE-2022-46169CRITICALunder attack01 Apr 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
exploit for CVE-2021-22911 in rust
CVE-2021-2291101 Apr 2023
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC3
CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。
CVE-2023-23397CRITICALunder attack31 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
Metasploit500
Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution
CVE-2023-28771CRITICALunder attack31 Mar 2023
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware31 Mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Exploit-DB
rconfig 3.9.7 - Sql Injection (Authenticated)
CVE-2022-45030HIGHwebappsphp31 Mar 2023
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may
41RISK
open
GitHub PoC
webmin <=1.920 - RCE via command injection vulnerability
CVE-2019-15107CRITICALunder attackransomware31 Mar 2023
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
previouspage 515 / 2,588next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.