Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,620 exploits
VulnCheck XDB
remote-with-credentials
CVE-2020-881330 Sep 2022
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open
GitHub PoC3
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Tool for mass testing ZeroLogon vulnerability CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALunder attack30 Sep 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware30 Sep 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44077CRITICALunder attack29 Sep 2022
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISK
open
GitHub PoC2
Golang Proof of Concept Exploit for CVE-2021-44077: PreAuth RCE in ManageEngine ServiceDesk Plus < 11306
CVE-2021-44077CRITICALunder attack29 Sep 2022
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014
100RISK
open
Metasploit600
Microsoft Exchange ProxyNotShell RCE
CVE-2022-41082HIGHunder attackransomware28 Sep 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Microsoft Exchange ProxyNotShell RCE
CVE-2022-41040HIGHunder attackransomware28 Sep 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC7
CVE-2022-39197
CVE-2022-39197MEDIUMunder attack27 Sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
GitHub PoC18
cobaltstrike4.5版本破解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
CVE-2022-39197MEDIUMunder attack26 Sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
GitHub PoC12
A loader for bitbucket 2022 rce (cve-2022-36804)
CVE-2022-36804HIGHunder attack26 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC317
CVE-2022-39197 漏洞补丁. CVE-2022-39197 Vulnerability Patch.
CVE-2022-39197MEDIUMunder attack26 Sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
VulnCheck XDB
initial-access
CVE-2022-36804HIGHunder attack26 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC
Pandora-research/CVE-2018-0114-Exploit
CVE-2018-011426 Sep 2022
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC12
A loader for bitbucket 2022 rce (cve-2022-36804)
CVE-2022-36804HIGHunder attack26 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC7
A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]
CVE-2022-36804HIGHunder attack25 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC8
CVE-2022-27925
CVE-2022-27925HIGHunder attackransomware25 Sep 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
VulnCheck XDB
local
CVE-2019-573625 Sep 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-1040CRITICALunder attack25 Sep 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC18
CVE-2022-1040
CVE-2022-1040CRITICALunder attack25 Sep 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-36804HIGHunder attack25 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC1
purple-WL/Cobaltstrike-RCE-CVE-2022-39197
CVE-2022-39197MEDIUMunder attack24 Sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
GitHub PoC2
CVE-2016-2098 POC
CVE-2016-209824 Sep 2022
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC17
Cobalt Strike RCE CVE-2022-39197
CVE-2022-39197MEDIUMunder attack24 Sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
VulnCheck XDB
initial-access
CVE-2022-36804HIGHunder attack24 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-39197MEDIUMunder attack24 Sep 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RISK
open
GitHub PoC
PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)
CVE-2022-36804HIGHunder attack24 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC3
You can find a python script to exploit the vulnerability on Bitbucket related CVE-2022-36804.
CVE-2022-36804HIGHunder attack24 Sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
previouspage 552 / 2,588next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.