Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,714 exploits
GitHub PoC
Adobe Acrobat Reader UAF vulnerability Exploit code
CVE-2020-9715HIGHunder attack29 Aug 2022
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RISK
open
GitHub PoC
CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
CVE-2017-891729 Aug 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
GitHub PoC
CVE-2017-7269 implemented in C#
CVE-2017-7269CRITICALunder attack29 Aug 2022
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
Metasploit400
WatchGuard XTM Firebox Unauthenticated Remote Command Execution
CVE-2022-26318CRITICALunder attack29 Aug 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack29 Aug 2022
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC
CVE-2017-7269 implemented in python3
CVE-2017-7269CRITICALunder attack28 Aug 2022
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
VulnCheck XDB
local
CVE-2022-0492HIGHunder attack27 Aug 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
GitHub PoC
A Docker image vulnerable to CVE-2020-7246.
CVE-2020-724627 Aug 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
GitHub PoC2
CVE-2022-0492-Container-Escape
CVE-2022-0492HIGHunder attack27 Aug 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
GitHub PoC5
Python Script to exploit Zimbra Auth Bypass + RCE (CVE-2022-27925)
CVE-2022-27925HIGHunder attackransomware26 Aug 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC9
Search for BTC coins on earlier versions of Bitcoin Core with critical vulnerability OpenSSL 0.9.8 CVE-2008-0166
CVE-2008-016626 Aug 2022
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISK
open
GitHub PoC1
CVE-2022-26134 web payload
CVE-2022-26134CRITICALunder attackransomware26 Aug 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware26 Aug 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC19
Zimbra CVE-2022-37042 Nuclei weaponized template
CVE-2022-37042CRITICALunder attackransomware25 Aug 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISK
open
GitHub PoC18
Oracle WebLogic CVE-2022-21371
CVE-2022-21371HIGH25 Aug 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
VulnCheck XDB
initial-access
CVE-2022-21907CRITICAL25 Aug 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-37042CRITICALunder attackransomware25 Aug 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISK
open
GitHub PoC
Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware25 Aug 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Metasploit600
Bitbucket Git Command Injection
CVE-2022-36804HIGHunder attack24 Aug 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC
nvchungkma/CVE-2021-40444-Microsoft-Office-Word-Remote-Code-Execution-
CVE-2021-40444HIGHunder attackransomware24 Aug 2022
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC9
SiJiDo/CVE-2022-22947
CVE-2022-22947CRITICALunder attack23 Aug 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC118
PrintNightmare (CVE-2021-34527) PoC Exploit
CVE-2021-34527HIGHunder attackransomware23 Aug 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34527HIGHunder attackransomware23 Aug 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2019-062323 Aug 2022
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
23RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware23 Aug 2022
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack23 Aug 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
local
CVE-2022-2586MEDIUMunder attack22 Aug 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISK
open
GitHub PoC
CVE-2022-26134-Console
CVE-2022-26134CRITICALunder attackransomware22 Aug 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC3
This is a modified version of the original GhostCat Exploit
CVE-2020-1938CRITICALunder attack21 Aug 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack21 Aug 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
previouspage 558 / 2,591next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.