Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,698 exploits
GitHub PoC2
Zabbix-SAML-Bypass: CVE-2022-23131
CVE-2022-23131CRITICALunder attack02 Sep 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
VulnCheck XDB
local
CVE-2021-31956HIGHunder attack02 Sep 2022
Windows NTFS Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC6
OpenSSL
CVE-2022-1292CRITICAL01 Sep 2022
The c_rehash script allows command injection
70RISK
open
GitHub PoC
shavchen/CVE-2022-26138
CVE-2022-26138CRITICALunder attack01 Sep 2022
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-0543CRITICALunder attack01 Sep 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
GitHub PoC
75ACOL/CVE-2022-22963
CVE-2022-22963CRITICALunder attack01 Sep 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Metasploit600
Symmetricom SyncServer Unauthenticated Remote Command Execution
CVE-2022-40022CRITICAL31 Aug 2022
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
85RISK
open
GitHub PoC84
CVE-2020-1472 C++
CVE-2020-1472MEDIUMunder attackransomware31 Aug 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
CVE-2022-24124 exploit
CVE-2022-2412431 Aug 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RISK
open
GitHub PoC
Proof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)
CVE-2022-0847HIGHunder attack31 Aug 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack31 Aug 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMunder attackransomware31 Aug 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC3
Oracle Weblogic RCE - CVE-2022-2109
CVE-2021-2109HIGH30 Aug 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISK
open
GitHub PoC5
Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3
CVE-2022-2463730 Aug 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RISK
open
GitHub PoC1
Apache Spark RCE - CVE-2022-33891
CVE-2022-33891HIGHunder attack29 Aug 2022
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
Metasploit400
WatchGuard XTM Firebox Unauthenticated Remote Command Execution
CVE-2022-26318CRITICALunder attack29 Aug 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISK
open
GitHub PoC
CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
CVE-2017-891729 Aug 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
GitHub PoC
CVE-2017-7269 implemented in C#
CVE-2017-7269CRITICALunder attack29 Aug 2022
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC
Adobe Acrobat Reader UAF vulnerability Exploit code
CVE-2020-9715HIGHunder attack29 Aug 2022
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack29 Aug 2022
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC
CVE-2017-7269 implemented in python3
CVE-2017-7269CRITICALunder attack28 Aug 2022
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
VulnCheck XDB
local
CVE-2022-0492HIGHunder attack27 Aug 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
GitHub PoC
A Docker image vulnerable to CVE-2020-7246.
CVE-2020-724627 Aug 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
GitHub PoC2
CVE-2022-0492-Container-Escape
CVE-2022-0492HIGHunder attack27 Aug 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
GitHub PoC5
Python Script to exploit Zimbra Auth Bypass + RCE (CVE-2022-27925)
CVE-2022-27925HIGHunder attackransomware26 Aug 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC1
CVE-2022-26134 web payload
CVE-2022-26134CRITICALunder attackransomware26 Aug 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC9
Search for BTC coins on earlier versions of Bitcoin Core with critical vulnerability OpenSSL 0.9.8 CVE-2008-0166
CVE-2008-016626 Aug 2022
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware26 Aug 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-21907CRITICAL25 Aug 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-37042CRITICALunder attackransomware25 Aug 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISK
open
previouspage 557 / 2,590next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.