Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,765cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,533 exploits
GitHub PoC
Joomla JCK Editor 6.4.4 - 'parent' SQL Injection
CVE-2018-1725429 Jan 2023
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISK
open
GitHub PoC
windows 10 SMB vulnerability
CVE-2020-0796CRITICALunder attackransomware29 Jan 2023
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
This is a vulnerability in the Linux kernel that was discovered and disclosed in 2017.
CVE-2017-548729 Jan 2023
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
GitHub PoC7
The official exploit for Froxlor Remote Code Execution CVE-2023-0315
CVE-2023-0315HIGH29 Jan 2023
Command Injection in froxlor/froxlor
78RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack29 Jan 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1725429 Jan 2023
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RISK
open
GitHub PoC
Exploit for CVE-2022-40684 vulnerability
CVE-2022-40684CRITICALunder attackransomware28 Jan 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-43798HIGHunder attack28 Jan 2023
Grafana path traversal
100RISK
open
GitHub PoC
This script implements a lab automation where I exploit CVE-2021-43798 to steal user secrets and then gain privileges on a Linux system.
CVE-2021-43798HIGHunder attack28 Jan 2023
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware27 Jan 2023
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH27 Jan 2023
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
VulnCheck XDB
initial-access
CVE-2014-238326 Jan 2023
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RISK
open
GitHub PoC1
Relativ3Pa1n/CVE-2014-2383-LFI-to-RCE-Escalation
CVE-2014-238326 Jan 2023
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RISK
open
GitHub PoC
vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional, Windows-specific issue known as CVE-2022-41953.
CVE-2022-41903CRITICAL26 Jan 2023
Integer overflow in `git archive`, `git log --format` leading to RCE in git
60RISK
open
GitHub PoC2
In Paradox Security System IPR512 web panel, an unauthenticated user can input JavaScript string, such as </script> that will overwrite configurations in the file "login.xml" and cause the login form to crash and make it unavailable.
CVE-2023-24709HIGH26 Jan 2023
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RISK
open
GitHub PoC2
DDoS Tool which exploits vulnerability CVE-2004-2449 from vendor GameSpy (now known as OpenSpy). User is prompted for input IP address, and port. (NOTE: Please use this responsibly, I made this as a proof of concept of vulnerability exploitation ONLY. I do not endorse DOSing, DDoSing, or cheating in any way. Use this at your own risk.)
CVE-2004-244925 Jan 2023
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial
23RISK
open
VulnCheck XDB
local
CVE-2023-2405525 Jan 2023
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,
23RISK
open
VulnCheck XDB
infoleak
CVE-2023-2405524 Jan 2023
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file,
23RISK
open
GitHub PoC1
A pwnkit N-Day exploit
CVE-2021-4034HIGHunder attackransomware24 Jan 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC6
A proof of concept exploit for a wordpress 5.6 media library vulnerability
CVE-2021-29447HIGH24 Jan 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC2
Drity Pipe Linux Kernel 1-Day Exploit
CVE-2022-0847HIGHunder attack24 Jan 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware24 Jan 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack24 Jan 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31706CRITICAL24 Jan 2023
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi
85RISK
open
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31704CRITICAL24 Jan 2023
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RISK
open
Metasploit600
VMware vRealize Log Insight Unauthenticated RCE
CVE-2022-31711MEDIUM24 Jan 2023
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen
53RISK
open
VulnCheck XDB
infoleak
CVE-2022-47966CRITICALunder attackransomware23 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALunder attackransomware23 Jan 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RISK
open
GitHub PoC8
A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17, <7.17.10, <7.21.4, <8.0.3, <8.1.2, <8.2.2, and <8.3.1
CVE-2022-36804HIGHunder attack23 Jan 2023
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC
it is the official Fix of Wordpress CVE-2018-6389.
CVE-2018-638923 Jan 2023
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
previouspage 529 / 2,585next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.