Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
77,772 exploits
GitHub PoC
CVE-2021-41773 Shodan scanner
CVE-2021-41773HIGHunder attackransomware12 May 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Essay (and PoCs) about CVE-2021-41773, a remote code execution vulnerability in Apache 2.4.49 🕸️
CVE-2021-41773HIGHunder attackransomware12 May 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DB
ExifTool 12.23 - Arbitrary Code Execution
CVE-2021-22204MEDIUMunder attacklocallinux11 May 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Exploit-DB
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
CVE-2021-31673webappsmultiple11 May 2022
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RISK
open
Exploit-DB
Navigate CMS 2.9.4 - Server-Side Request Forgery (SSRF) (Authenticated)
CVE-2022-28117webappsphp11 May 2022
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RISK
open
Exploit-DB
WordPress Plugin Blue Admin 21.06.01 - Cross-Site Request Forgery (CSRF)
CVE-2021-24581webappsphp11 May 2022
Blue Admin <= 21.06.01 - CSRF to Stored Cross-Site Scripting (XSS)
23RISK
open
Exploit-DB
DLINK DAP-1620 A1 v1.01 - Directory Traversal
CVE-2021-46381remotehardware11 May 2022
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RISK
open
Exploit-DB
Bookeen Notea - Directory Traversal
CVE-2021-45783remoteandroid11 May 2022
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to
23RISK
open
Exploit-DB
Anuko Time Tracker - SQLi (Authenticated)
CVE-2022-24707HIGHwebappsphp11 May 2022
SQL injection in anuko timetracker
41RISK
open
Exploit-DB
DLINK DIR850 - Open Redirect
CVE-2021-46379remotehardware11 May 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RISK
open
Exploit-DB
TLR-2005KSH - Arbitrary File Upload
CVE-2021-45428webappshardware11 May 2022
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RISK
open
Exploit-DB
MyBB 1.8.29 - MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-24734HIGHwebappsphp11 May 2022
Remote code execution in mybb
78RISK
open
Exploit-DB
Akka HTTP 10.1.14 - Denial of Service
CVE-2021-42697remotemultiple11 May 2022
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RISK
open
Exploit-DB
WebTareas 2.4 - Blind SQLi (Authenticated)
CVE-2021-43481webappsphp11 May 2022
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RISK
open
GitHub PoC
Research and proof of concept related to CVE-2022-1388.
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC2
CVE-2022-1388 Scanner
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Exploit-DB
PHProjekt PhpSimplyGest v1.3. - Stored Cross-Site Scripting (XSS)
CVE-2022-27308webappsphp11 May 2022
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RISK
open
Exploit-DB
Explore CMS 1.0 - SQL Injection
CVE-2022-27412webappsphp11 May 2022
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RISK
open
GitHub PoC5
AmirHoseinTangsiriNET/CVE-2022-1388-Scanner
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Exploit-DB
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
CVE-2022-29457remotewindows11 May 2022
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131
23RISK
open
Exploit-DB
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
CVE-2022-1103webappsphp11 May 2022
Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
28RISK
open
GitHub PoC
CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Exploit-DB
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
CVE-2022-28213remotemultiple11 May 2022
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n
28RISK
open
Exploit-DB
Apache CouchDB 3.2.1 - Remote Code Execution (RCE)
CVE-2022-24706CRITICALunder attackremotelinux11 May 2022
Remote Code Execution Vulnerability in Packaging
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
CVE-2013-471011 May 2022
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware11 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
previouspage 580 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.