Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
77,772 exploits
GitHub PoC16
may the poc with you
CVE-2022-1040CRITICALunder attack06 May 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC53
K23605346: BIG-IP iControl REST vulnerability CVE-2022-1388
CVE-2022-1388CRITICALunder attackransomware05 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC1
1
CVE-2022-29464CRITICALunder attackransomware05 May 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC
CVE-2022-22954 analyst
CVE-2022-22954CRITICALunder attackransomware05 May 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open
GitHub PoC25
Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)
CVE-2022-1388CRITICALunder attackransomware05 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware05 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware05 May 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware05 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Metasploit600
F5 BIG-IP iControl RCE via REST Authentication Bypass
CVE-2022-1388CRITICALunder attackransomware04 May 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
Metasploit600
DotCMS RCE via Arbitrary File Upload.
CVE-2022-26352CRITICALunder attackransomware03 May 2022
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req
100RISK
open
GitHub PoC13
PoC of CVE-2022-24707
CVE-2022-24707HIGH03 May 2022
SQL injection in anuko timetracker
41RISK
open
VulnCheck XDB
local
CVE-2021-22204MEDIUMunder attack03 May 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC
CVE-2018-17553 PoC
CVE-2018-1755303 May 2022
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RISK
open
GitHub PoC12
Exploit for CVE-2021-3560 (Polkit) - Local Privilege Escalation
CVE-2021-3560HIGHunder attack02 May 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC
Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware02 May 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack02 May 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC60
yuanLink/CVE-2022-26809
CVE-2022-26809CRITICAL01 May 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
CVE-2021-44228 Log4j Summary
CVE-2021-44228CRITICALunder attackransomware30 Apr 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack30 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC25
PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)
CVE-2021-3560HIGHunder attack30 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2018-20250HIGHunder attackransomware29 Apr 2022
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware29 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack29 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC116
PolicyKit CVE-2021-3560 Exploit (Authentication Agent)
CVE-2021-3560HIGHunder attack29 Apr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC
Enokiy/spring-RCE-CVE-2022-22965
CVE-2022-22965CRITICALunder attack29 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC2
CVE-2022-29464 POC exploit
CVE-2022-29464CRITICALunder attackransomware29 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC8
This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.
CVE-2018-1942229 Apr 2022
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISK
open
Metasploit600
Zyxel Firewall ZTP Unauthenticated Command Injection
CVE-2022-30525CRITICALunder attack28 Apr 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack28 Apr 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC13
A tool for extracting, modifying, and crafting ASDM binary packages (CVE-2022-20829)
CVE-2022-20829CRITICAL28 Apr 2022
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
48RISK
open
previouspage 584 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.