Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
77,533 exploits
GitHub PoC159
Exploit for the CVE-2023-23397
CVE-2023-23397CRITICALunder attack15 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-23397CRITICALunder attack15 Mar 2023
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC15
Windows Network File System Remote exploit for CVE-2022-30136
CVE-2022-30136CRITICAL15 Mar 2023
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
Metasploit300
Dolibarr 16 pre-auth contact database dump
CVE-2023-3356814 Mar 2023
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's
23RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288914 Mar 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
Metasploit600
Adobe ColdFusion Unauthenticated Remote Code Execution
CVE-2023-26360HIGHunder attack14 Mar 2023
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
GitHub PoC
Batch scanning site.
CVE-2020-3187CRITICAL14 Mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
local
CVE-2022-30190HIGHunder attackransomware14 Mar 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-3187CRITICAL14 Mar 2023
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
GitHub PoC3
An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft
CVE-2021-44228CRITICALunder attackransomware14 Mar 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Implementation of FOLLINA-CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware14 Mar 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
CVE-2022-22963 RCE PoC in python
CVE-2022-22963CRITICALunder attack13 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC4
A Tool for scanning CVE-2017-9841 with multithread
CVE-2017-9841CRITICALunder attack13 Mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack13 Mar 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
Metasploit600
Lexmark Device Embedded Web Server RCE
CVE-2023-26068CRITICAL13 Mar 2023
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
68RISK
open
Metasploit600
PaperCut PaperCutNG Authentication Bypass
CVE-2023-27350CRITICALunder attackransomware13 Mar 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC1
Syd-SydneyJr/CVE-2021-45010
CVE-2021-4501013 Mar 2023
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack13 Mar 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC1
Demonstrable Proof of Concept Exploit for Spring4Shell Vulnerability (CVE-2022-22965)
CVE-2022-22965CRITICALunder attack12 Mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
local
CVE-2022-21894MEDIUM11 Mar 2023
Secure Boot Security Feature Bypass Vulnerability
33RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack11 Mar 2023
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack11 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC1
Laravel RCE CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware11 Mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC26
CVE-2023-21839工具
CVE-2023-21839HIGHunder attack11 Mar 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC
h1bAna/CVE-2017-5123
CVE-2017-512311 Mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISK
open
GitHub PoC15
This is poc of CVE-2022-46169 authentication bypass and remote code execution
CVE-2022-46169CRITICALunder attack11 Mar 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
python 2.7
CVE-2023-23752MEDIUMunder attack11 Mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware11 Mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
ahiahai242/CVE-2017-5123
CVE-2017-512311 Mar 2023
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RISK
open
previouspage 520 / 2,585next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.