Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,455Referência 22,523GitHub PoC 14,289VulnCheck XDB 8,710Nuclei 4,319Metasploit 3,476✓ verified onlyrecentpopularrisk
77,533 exploits
VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC★ 2
CVE-2018-16763 FuelCMS 1.4 Remote Code Execution, this version of FuelCMS is still vulnerable until now
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗GitHub PoC
A Proof of Concept for the CVE-2021-46398 flaw exploitation
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RISK
open ↗GitHub PoC
User friendly Spring4Shell POC
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗VulnCheck XDB
remote-with-credentials
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISK
open ↗GitHub PoC
ryan412/CVE-2022-48197
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RISK
open ↗GitHub PoC
Trinadh465/frameworks_minikin_AOSP10_r33_CVE-2022-20473
In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c
48RISK
open ↗VulnCheck XDB
infoleak
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFi
38RISK
open ↗VulnCheck XDB
initial-access
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/managemen
60RISK
open ↗GitHub PoC
philippedixon/CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 1
CVE-2020-17382 Windows 10 x64 2004 Build 19041.264 Exploit
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RISK
open ↗GitHub PoC
Exploit for CVE-2007-4560 (ClamAV Milter Sendmail 0.91.2 Remote Code Execution)
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary command
60RISK
open ↗GitHub PoC
Dirty Pipe Kernel Vulnerability Exploit
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC
sqsec/log4j2_CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC★ 1
CVE-2022-30190(follina)
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 19
The results of my small term paper on the topic of the Internet of Vulnerable Things and the exploit for CVE-2022-48194.
TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a De
53RISK
open ↗VulnCheck XDB
client-side
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open ↗Metasploit400
SugarCRM unauthenticated Remote Code Execution (RCE)
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because o
100RISK
open ↗VulnCheck XDB
client-side
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open ↗GitHub PoC★ 11
Working Proof of Concept Exploit for CVE-2018-17463
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbit
100RISK
open ↗GitHub PoC
Learn about the vulnerability known as PrintNightmare (CVE-2021-1675) and (CVE-2021-34527)
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 102
CVE-2022-22965\Spring-Core-RCE核弹级别漏洞的rce图形化GUI一键利用工具,基于JavaFx开发,图形化操作更简单,提高效率。
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC
cve based on vulnerable cisco's Archer A7 routers
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RISK
open ↗GitHub PoC
Exploit i used in HTB
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗GitHub PoC
michealadams30/Cve-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.