Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,866cataloged exploits
35,812CVEs with public exploitation
24,695lab-tested
77,772 exploits
GitHub PoC
My research about CVE-2021-4034
CVE-2021-4034HIGHunder attackransomware24 Apr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC5
mariomamo/CVE-2022-22965
CVE-2022-22965CRITICALunder attack23 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
CVE-2022-26809-RCE
CVE-2022-26809CRITICAL23 Apr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack23 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
client-side
CVE-2017-0199HIGHunder attackransomware22 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
A python script/generator, for generating and exploiting Microsoft vulnerability
CVE-2017-0199HIGHunder attackransomware22 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC
This repository contains a PoC for remote code execution CVE-2022-26809
CVE-2022-26809CRITICAL22 Apr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open
GitHub PoC5
WSO2 RCE (CVE-2022-29464)
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC1
0xAgun/CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC5
cve-2022-29464 批量脚本
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC3
Repository containing nse script for vulnerability CVE-2022-29464 known as WSO2 RCE.
CVE-2022-29464CRITICALunder attackransomware22 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC2
Pre-auth RCE bug CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware21 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC2
tufanturhan/wso2-rce-cve-2022-29464
CVE-2022-29464CRITICALunder attackransomware21 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC1
c4mx/CVE-2022-22965_PoC
CVE-2022-22965CRITICALunder attack21 Apr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-1092421 Apr 2022
The ebook-download plugin before 1.2 for WordPress has directory traversal.
43RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware20 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
client-side
CVE-2017-0199HIGHunder attackransomware20 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC1
Phantomlancer123/CVE-2017-0199
CVE-2017-0199HIGHunder attackransomware20 Apr 2022
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack20 Apr 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack20 Apr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
CVE-2021-4034 PoC
CVE-2021-4034HIGHunder attackransomware20 Apr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
MS CVE 2019-0708 Python Exploit
CVE-2019-0708CRITICALunder attackransomware20 Apr 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
CVE-2017-9841批量扫描及利用脚本。PHPUnit是其中的一个基于PHP的测试框架。 PHPUnit 4.8.28之前的版本和5.6.3之前的5.x版本中的Util/PHP/eval-stdin.php文件存在安全漏洞。远程攻击者可通过发送以‘<?php’字符串开头的HTTP POST数据利用该漏洞执行任意PHP代码。
CVE-2017-9841CRITICALunder attack20 Apr 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware20 Apr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC377
WSO2 RCE (CVE-2022-29464) exploit and writeup.
CVE-2022-29464CRITICALunder attackransomware20 Apr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
Exploit-DB
Zyxel NWA-1100-NH - Command Injection
CVE-2021-4039CRITICALremotehardware19 Apr 2022
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to exec
70RISK
open
Exploit-DB
WordPress Plugin Popup Maker 1.16.5 - Stored Cross-Site Scripting (Authenticated)
CVE-2022-1104webappsphp19 Apr 2022
Popup Maker < 1.16.5 - Admin+ Stored Cross-Site Scripting
35RISK
open
Exploit-DB
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
CVE-2022-24181webappsphp19 Apr 2022
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to
38RISK
open
VulnCheck XDB
infoleak
CVE-2023-20198CRITICALunder attack19 Apr 2022
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
previouspage 586 / 2,593next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.