Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
77,533 exploits
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL15 Feb 2023
Code Injection in pyload/pyload
85RISK
open
GitHub PoC6
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated) POC Exploit (CVE-2022-45701)
CVE-2022-45701HIGH15 Feb 2023
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISK
open
GitHub PoC
PaloAlto EXP(CVE-2017-15944)
CVE-2017-15944CRITICALunder attack15 Feb 2023
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-15944CRITICALunder attack15 Feb 2023
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RISK
open
VulnCheck XDB
local
CVE-2023-2405514 Feb 2023
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,
23RISK
open
GitHub PoC16
Dompdf RCE PoC Exploit - CVE-2022-28368
CVE-2022-2836813 Feb 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISK
open
GitHub PoC27
CVE-2022-44268 ImageMagick Arbitrary File Read - Proof of Concept exploit
CVE-2022-44268MEDIUM13 Feb 2023
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
VulnCheck XDB
client-side
CVE-2023-21608HIGHunder attack13 Feb 2023
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
83RISK
open
GitHub PoC12
Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit
CVE-2023-21608HIGHunder attack13 Feb 2023
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
83RISK
open
VulnCheck XDB
local
CVE-2022-30190HIGHunder attackransomware13 Feb 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
yrkuo/CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware13 Feb 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2022-46689HIGH12 Feb 2023
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RISK
open
VulnCheck XDB
initial-access
CVE-2022-44877CRITICALunder attack11 Feb 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
GitHub PoC
PoC Exploit for RCE vulnerability in DedeCMS v6.1.9
CVE-2022-44118CRITICAL11 Feb 2023
dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
48RISK
open
GitHub PoC4
Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)
CVE-2022-44877CRITICALunder attack11 Feb 2023
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-47986CRITICALunder attackransomware10 Feb 2023
IBM Aspera Faspex code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-0669HIGHunder attackransomware10 Feb 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
GitHub PoC102
CVE-2023-0669 GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.
CVE-2023-0669HIGHunder attackransomware10 Feb 2023
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open
Metasploit600
Lucee Authenticated Scheduled Job Code Execution
CVE-2025-34074CRITICAL10 Feb 2023
Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
63RISK
open
VulnCheck XDB
initial-access
CVE-2023-25194HIGH09 Feb 2023
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RISK
open
GitHub PoC
Bhathiya404/Exploiting-Stagefright-Vulnerability-CVE-2015-3864
CVE-2015-386409 Feb 2023
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISK
open
GitHub PoC3
Below code takes advantage of a known vulnerability [Dirty COW (CVE-2016-5195)] 🔥
CVE-2016-5195HIGHunder attack08 Feb 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC10
( Wordpress Exploit ) Wordpress Multiple themes - Unauthenticated Arbitrary File Upload
CVE-2022-0316CRITICAL08 Feb 2023
Multiple themes - Unauthenticated Arbitrary File Upload
48RISK
open
VulnCheck XDB
initial-access
CVE-2021-44168LOWunder attack08 Feb 2023
A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.
58RISK
open
GitHub PoC1
CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.
CVE-2021-44228CRITICALunder attackransomware08 Feb 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-21661HIGH08 Feb 2023
SQL injection in WordPress
78RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack08 Feb 2023
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC2
Demonstration of the SQL injection vulnerability in wordpress 5.8.2
CVE-2022-21661HIGH08 Feb 2023
SQL injection in WordPress
78RISK
open
GitHub PoC1
HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B HTTP configuration page Cross Site Scripting (XSS) Vulnerability
CVE-2022-48311CRITICAL07 Feb 2023
**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR
48RISK
open
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALunder attackransomware07 Feb 2023
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
previouspage 526 / 2,585next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.