Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
77,724 exploits
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack23 Aug 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC118
PrintNightmare (CVE-2021-34527) PoC Exploit
CVE-2021-34527HIGHunder attackransomware23 Aug 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware23 Aug 2022
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC9
SiJiDo/CVE-2022-22947
CVE-2022-22947CRITICALunder attack23 Aug 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-34527HIGHunder attackransomware23 Aug 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2019-062323 Aug 2022
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
23RISK
open
GitHub PoC
CVE-2022-26134-Console
CVE-2022-26134CRITICALunder attackransomware22 Aug 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
local
CVE-2022-2586MEDIUMunder attack22 Aug 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RISK
open
GitHub PoC3
This is a modified version of the original GhostCat Exploit
CVE-2020-1938CRITICALunder attack21 Aug 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack21 Aug 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware20 Aug 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC
navokus/CVE-2022-27925
CVE-2022-27925HIGHunder attackransomware20 Aug 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC43
Zimbra CVE-2022-27925 PoC
CVE-2022-27925HIGHunder attackransomware20 Aug 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
VulnCheck XDB
client-side
CVE-2022-1802HIGH20 Aug 2022
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have
46RISK
open
Metasploit600
FLIR AX8 unauthenticated RCE
CVE-2022-3706119 Aug 2022
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open
GitHub PoC
Advanced Comment System 1.0 - Remote Command Execution (RCE)
CVE-2009-462319 Aug 2022
Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbi
23RISK
open
GitHub PoC
CVE-2018-0798复现
CVE-2018-0798HIGHunder attack19 Aug 2022
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows
93RISK
open
GitHub PoC
miko550/CVE-2022-27925
CVE-2022-27925HIGHunder attackransomware19 Aug 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC7
GreyNoise-Intelligence/Zimbra_CVE-2022-37042-_CVE-2022-27925
CVE-2022-37042CRITICALunder attackransomware18 Aug 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISK
open
GitHub PoC5
CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸
CVE-2022-0847HIGHunder attack18 Aug 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
tharindudh/tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware18 Aug 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
local
CVE-2022-21894MEDIUM18 Aug 2022
Secure Boot Security Feature Bypass Vulnerability
33RISK
open
Metasploit300
Rancher Authenticated API Credential Exposure
CVE-2021-36782CRITICAL18 Aug 2022
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
63RISK
open
GitHub PoC17
A powershell poc to load and automatically run Certify and Rubeus from memory.
CVE-2022-26923HIGHunder attack17 Aug 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
Remote code execution in CA APM Team Center (Wily Introscope)
CVE-2020-6364CRITICAL17 Aug 2022
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an att
48RISK
open
VulnCheck XDB
initial-access
CVE-2020-3566517 Aug 2022
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in
60RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-34721CRITICAL16 Aug 2022
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
infoleak
CVE-2019-9670CRITICALunder attack15 Aug 2022
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
GitHub PoC2
CVE-2017-0199复现
CVE-2017-0199HIGHunder attackransomware15 Aug 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-949615 Aug 2022
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open
previouspage 559 / 2,591next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.