Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,620 exploits
GitHub PoC2
dhammon/pfBlockerNg-CVE-2022-40624
CVE-2022-40624CRITICAL15 Sep 2022
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host
68RISK
open
GitHub PoC
CVE-2022-37204 POC
CVE-2022-37204CRITICAL15 Sep 2022
Final CMS 5.1.0 is vulnerable to SQL Injection.
48RISK
open
VulnCheck XDB
client-side
CVE-2022-30190HIGHunder attackransomware15 Sep 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-42013CRITICALunder attackransomware15 Sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
client-side
CVE-2021-42013CRITICALunder attackransomware15 Sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
mightysai1997/cve-2021-42013L
CVE-2021-42013CRITICALunder attackransomware15 Sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
mightysai1997/cve-2021-42013.get
CVE-2021-42013CRITICALunder attackransomware15 Sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
mightysai1997/cve-2021-42013
CVE-2021-42013CRITICALunder attackransomware15 Sep 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
kernel-cyber/CVE-2009-4623
CVE-2009-462315 Sep 2022
Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Gitea 1.16.6 - Remote Code Execution (RCE) (Metasploit)
CVE-2022-30781webappsmultiple15 Sep 2022
Gitea before 1.16.7 does not escape git fetch remote.
60RISK
open
GitHub PoC2
A proof of concept for CVE-2022-30190 (Follina).
CVE-2022-30190HIGHunder attackransomware15 Sep 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Sep 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Free MP3 CD Ripper 2.6 版本中存在栈缓冲区溢出漏洞 (CVE-2019-9766),远程攻击者可借助特制的 .mp3 文件利用该漏洞执行任意代码。
CVE-2019-976614 Sep 2022
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISK
open
GitHub PoC
ApacheSolrRCE(CVE-2019-0193)一键写shell,原理是通过代码执行的java文件流写的马。
CVE-2019-0193HIGHunder attack13 Sep 2022
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
GitHub PoC5
CVE-2022-34715-POC pcap
CVE-2022-34715CRITICAL13 Sep 2022
Windows Network File System Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2019-0193HIGHunder attack13 Sep 2022
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISK
open
GitHub PoC7
Automation to validate the impact of the vulnerability CVE-2022-1292 on a specific system.
CVE-2022-1292CRITICAL13 Sep 2022
The c_rehash script allows command injection
70RISK
open
GitHub PoC2
bl4ck574r/CVE-2019-17662
CVE-2019-1766213 Sep 2022
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISK
open
Metasploit500
Ubuntu Enlightenment Mount Priv Esc
CVE-2022-37706HIGH13 Sep 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-3007512 Sep 2022
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RISK
open
GitHub PoC8
POC exploit for CVE-2015-4133
CVE-2015-413312 Sep 2022
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RISK
open
GitHub PoC3
CVE-2022-27925 nuclei template
CVE-2022-27925HIGHunder attackransomware12 Sep 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware12 Sep 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC1
M4fiaB0y/CVE-2022-30075
CVE-2022-3007512 Sep 2022
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RISK
open
previouspage 555 / 2,588next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.