Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
77,620 exploits
VulnCheck XDB
initial-access
CVE-2022-4288922 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
client-side
CVE-2022-4288922 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-39197MEDIUMunder attack22 Oct 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
GitHub PoC
CVE-2017-0785
CVE-2017-078522 Oct 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open
GitHub PoC3
python script for CVE-2022-42889
CVE-2022-4288922 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
Dockerized PoC for CVE-2022-42889 Text4Shell
CVE-2022-4288922 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC1
CVE-2022-42889 Text4Shell Exploit POC
CVE-2022-4288922 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC2
humbss/CVE-2022-42889
CVE-2022-4288921 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288921 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
CVE-2007-4559 - Polemarch exploit
CVE-2007-4559CRITICAL21 Oct 2022
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISK
open
GitHub PoC3
This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability
CVE-2022-4288921 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC3
通过 jvm 启动参数 以及 jps pid进行拦截非法参数
CVE-2022-4288920 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack20 Oct 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-41040HIGHunder attackransomware20 Oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC35
the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated attacker can use the vulnerability to elevate privileges.
CVE-2022-41040HIGHunder attackransomware20 Oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889
CVE-2022-4288920 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC8
Proof of Concept Appliction for testing CVE-2022-42889
CVE-2022-4288920 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
Automated Exploit for CVE-2017-9841 (eval-stdin.php vulnerable file)
CVE-2017-9841CRITICALunder attack20 Oct 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
infoleak
CVE-2022-40684CRITICALunder attackransomware19 Oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
CVE-2022-42889 dockerized sample application (Apache Commons Text RCE)
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
inj3ction/CVE-2017-7921-EXP
CVE-2017-7921CRITICALunder attack19 Oct 2022
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
client-side
CVE-2017-7921CRITICALunder attack19 Oct 2022
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
onlyHerold22/CVE-2022-27925-PoC
CVE-2022-27925HIGHunder attackransomware19 Oct 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
Metasploit600
SolarWinds Information Service (SWIS) .NET Deserialization From AMQP RCE
CVE-2022-38108HIGH19 Oct 2022
SolarWinds Platform Deserialization of Untrusted Data
48RISK
open
GitHub PoC
Vulnerability to CVE-2021-4034 Pwnkit
CVE-2021-4034HIGHunder attackransomware19 Oct 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware19 Oct 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC
eunomie/cve-2022-42889-check
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC57
Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.
CVE-2022-4288919 Oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
previouspage 545 / 2,588next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.