Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,588 exploits
VulnCheck XDB
infoleak
CVE-2022-241406 Dec 2022
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a
60RISK
open
VulnCheck XDB
infoleak
CVE-2018-742206 Dec 2022
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware06 Dec 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
For CVE-2022-33891 Apache Spark: Emulation and Detection by West Shepherd
CVE-2022-33891HIGHunder attack06 Dec 2022
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
GitHub PoC1
amitlttwo/CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware06 Dec 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
Exploit for path transversal vulnerability in apache
CVE-2021-41773HIGHunder attackransomware05 Dec 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware05 Dec 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit600
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALunder attack05 Dec 2022
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Spring-CVE-2010-1622
CVE-2010-162205 Dec 2022
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISK
open
GitHub PoC
Exploit from perception point
CVE-2016-072804 Dec 2022
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open
VulnCheck XDB
local
CVE-2016-072804 Dec 2022
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISK
open
Metasploit300
Mirage firewall for QubesOS 0.8.0-0.8.3 Denial of Service (DoS) Exploit
CVE-2022-46770HIGH04 Dec 2022
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of s
61RISK
open
GitHub PoC
XiangSi-Howard/CTF---CVE-2011-2523
CVE-2011-252303 Dec 2022
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC5
CVE-2022-24112_POC
CVE-2022-24112CRITICALunder attack03 Dec 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-24112CRITICALunder attack03 Dec 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open
GitHub PoC1
JoshMorrison99/CVE-2016-3714
CVE-2016-3714HIGHunder attack02 Dec 2022
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISK
open
GitHub PoC
lkduy2602/Detecting-CVE-2018-15708-Vulnerabilities
CVE-2018-1570801 Dec 2022
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-41082HIGHunder attackransomware01 Dec 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
Exchange CVE '22
CVE-2022-41082HIGHunder attackransomware01 Dec 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
SilasSpringer/CVE-2018-10933
CVE-2018-10933CRITICAL01 Dec 2022
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
A Terraform module to launch Rancher 2.6.6 for blog article about CVE-2021-36782
CVE-2021-36782CRITICAL01 Dec 2022
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
63RISK
open
GitHub PoC2
Validation of Arbitrary File Read Vulnerabilities in Dell OpenManage Server Administrator (OMSA) - CVE-2016-4004, CVE-2021-21514 and CVE-2020-5377.
CVE-2016-400430 Nov 2022
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RISK
open
GitHub PoC3
revanmalang/CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware30 Nov 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC2
Validation of Arbitrary File Read Vulnerabilities in Dell OpenManage Server Administrator (OMSA) - CVE-2016-4004, CVE-2021-21514 and CVE-2020-5377.
CVE-2020-5377CRITICAL30 Nov 2022
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware30 Nov 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
client-side
CVE-2022-41412HIGH29 Nov 2022
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and exec
56RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack29 Nov 2022
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC1
fei9747/CVE-2021-3493
CVE-2021-3493HIGHunder attack29 Nov 2022
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack29 Nov 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
fei9747/CVE-2017-16995
CVE-2017-1699529 Nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
previouspage 537 / 2,587next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.