Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,573GitHub PoC 14,316VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
77,724 exploits
GitHub PoC★ 14
Wordpress 5.8.2 CVE-2022-21661 Vuln enviroment POC exploit
SQL injection in WordPress
78RISK
open ↗GitHub PoC★ 10
CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open ↗GitHub PoC★ 10
CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open ↗GitHub PoC
CVE-2018-17456复现
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open ↗GitHub PoC★ 1
CVE-2022-1609 WordPress Weblizar后门
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open ↗GitHub PoC
A PoC / methodology to exploit CVE-2017-6516
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RISK
open ↗VulnCheck XDB
initial-access
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, an
35RISK
open ↗VulnCheck XDB
initial-access
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open ↗VulnCheck XDB
initial-access
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open ↗GitHub PoC★ 2
FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗VulnCheck XDB
initial-access
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗GitHub PoC★ 1
sudo提权漏洞CVE-2021-3156复现代码
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗GitHub PoC★ 5
Python script to exploit CVE-2022-29464 (mass mode)
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open ↗Exploit-DB✓ VexDay Proof
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2)
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open ↗GitHub PoC
yuuki1967/CVE-2021-44228-Apache-Log4j-Rce
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗VulnCheck XDB
remote-with-credentials
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
85RISK
open ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 71
Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
85RISK
open ↗GitHub PoC
b1ackros337/CVE-2020-25213
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open ↗VulnCheck XDB
initial-access
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open ↗Metasploit300
SuiteCRM authenticated SQL injection in export functionality
SQL Injection in salesagility/suitecrm
28RISK
open ↗VulnCheck XDB
initial-access
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
50RISK
open ↗GitHub PoC
Satheesh575555/external_expat_AOSP10_r33_CVE-2022-25235
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT
48RISK
open ↗VulnCheck XDB
initial-access
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
SDT-CW3B1 1.1.0 - OS Command Injection
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open ↗GitHub PoC★ 1
Vulnearability Report of the New Jersey official site
jQuery has a potential XSS vulnerability
55RISK
open ↗GitHub PoC
Vulnearability Report of the New Jersey official site
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open ↗GitHub PoC★ 1
Vulnearability Report of the New Jersey official site
Potential XSS vulnerability in jQuery
85RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.