Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,620 exploits
VulnCheck XDB
initial-access
CVE-2022-4288904 Nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC15
Proof of Concept for CVE-2022-42889 (Text4Shell Vulnerability)
CVE-2022-4288904 Nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC35
A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692
CVE-2022-31692CRITICAL03 Nov 2022
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v
48RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack03 Nov 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC30
利用sudo提权,只针对cnetos7
CVE-2021-3156HIGHunder attack03 Nov 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
POCsuite与goland实现华为HG532路由器命令注入CVE-2017-17215 POC
CVE-2017-1721502 Nov 2022
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RISK
open
GitHub PoC2
CVE-2022-42889 Blind-RCE Nuclei Template
CVE-2022-4288902 Nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
Metasploit600
Authenticated RCE in Splunk (SimpleXML dashboard PDF generation)
CVE-2022-43571HIGH02 Nov 2022
Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
41RISK
open
GitHub PoC15
CVE-­2021­-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发
CVE-2021-1732HIGHunder attackransomware01 Nov 2022
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC9
apache路径穿越漏洞poc&exp
CVE-2021-41773HIGHunder attackransomware01 Nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC7
python编写的apache路径穿越poc&exp
CVE-2021-41773HIGHunder attackransomware01 Nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware01 Nov 2022
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware01 Nov 2022
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
GitHub PoC7
SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit
CVE-2017-7494CRITICALunder attackransomware01 Nov 2022
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware01 Nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware01 Nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC4
By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:
CVE-2018-14847CRITICALunder attack31 Oct 2022
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALunder attack31 Oct 2022
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
Metasploit600
Clinic's Patient Management System 1.0 - Unauthenticated RCE
CVE-2022-40471CRITICAL31 Oct 2022
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RISK
open
VulnCheck XDB
initial-access
CVE-2022-1040CRITICALunder attack30 Oct 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC1
jehovah2002/CVE-2021-4034-pwnkit
CVE-2021-4034HIGHunder attackransomware30 Oct 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC2
This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication
CVE-2022-1040CRITICALunder attack30 Oct 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC17
POC for CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability.
CVE-2022-21907CRITICAL29 Oct 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack29 Oct 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL29 Oct 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALunder attackransomware28 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC11
hughink/CVE-2022-40684
CVE-2022-40684CRITICALunder attackransomware28 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-43890HIGHunder attackransomware28 Oct 2022
Windows AppX Installer Spoofing Vulnerability
76RISK
open
GitHub PoC2
Exploit Fortigate - CVE-2022-40684
CVE-2022-40684CRITICALunder attackransomware27 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC14
CVE-2023-29478 - BiblioCraft File Manipulation/Remote Code Execution exploit affecting BiblioCraft versions prior to v2.4.6
CVE-2023-29478CRITICAL27 Oct 2022
BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to a
48RISK
open
previouspage 543 / 2,588next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.