Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
77,724 exploits
GitHub PoC14
Wordpress 5.8.2 CVE-2022-21661 Vuln enviroment POC exploit
CVE-2022-21661HIGH28 May 2022
SQL injection in WordPress
78RISK
open
GitHub PoC10
CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合
CVE-2022-1388CRITICALunder attackransomware28 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC10
CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合
CVE-2020-5902CRITICALunder attackransomware28 May 2022
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC
CVE-2018-17456复现
CVE-2018-1745627 May 2022
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
GitHub PoC1
CVE-2022-1609 WordPress Weblizar后门
CVE-2022-1609CRITICAL27 May 2022
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open
GitHub PoC
A PoC / methodology to exploit CVE-2017-6516
CVE-2017-651627 May 2022
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RISK
open
VulnCheck XDB
initial-access
CVE-2016-063827 May 2022
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, an
35RISK
open
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALunder attack27 May 2022
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1609CRITICAL27 May 2022
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISK
open
GitHub PoC2
FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523
CVE-2011-252327 May 2022
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack26 May 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware26 May 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC1
sudo提权漏洞CVE-2021-3156复现代码
CVE-2021-3156HIGHunder attack26 May 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC5
Python script to exploit CVE-2022-29464 (mass mode)
CVE-2022-29464CRITICALunder attackransomware26 May 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
Exploit-DBVexDay Proof
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2)
CVE-2020-7246webappsphp25 May 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISK
open
GitHub PoC
yuuki1967/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALunder attackransomware25 May 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-0540CRITICAL25 May 2022
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
85RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware25 May 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC71
Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)
CVE-2022-0540CRITICAL25 May 2022
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
85RISK
open
GitHub PoC4
CVE-2022-1292
CVE-2022-1292CRITICAL24 May 2022
The c_rehash script allows command injection
70RISK
open
GitHub PoC
b1ackros337/CVE-2020-25213
CVE-2020-25213CRITICALunder attack24 May 2022
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-4642224 May 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
Metasploit300
SuiteCRM authenticated SQL injection in export functionality
CVE-2023-5350MEDIUM24 May 2022
SQL Injection in salesagility/suitecrm
28RISK
open
VulnCheck XDB
initial-access
CVE-2022-2297224 May 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
50RISK
open
GitHub PoC
Satheesh575555/external_expat_AOSP10_r33_CVE-2022-25235
CVE-2022-25235CRITICAL24 May 2022
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT
48RISK
open
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALunder attackransomware24 May 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
SDT-CW3B1 1.1.0 - OS Command Injection
CVE-2021-4642224 May 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
GitHub PoC1
Vulnearability Report of the New Jersey official site
CVE-2020-11022MEDIUM23 May 2022
jQuery has a potential XSS vulnerability
55RISK
open
GitHub PoC
Vulnearability Report of the New Jersey official site
CVE-2019-1135823 May 2022
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
GitHub PoC1
Vulnearability Report of the New Jersey official site
CVE-2020-11023MEDIUMunder attack23 May 2022
Potential XSS vulnerability in jQuery
85RISK
open
previouspage 576 / 2,591next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.