Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,899cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,600GitHub PoC 14,322VulnCheck XDB 8,722Nuclei 4,320Metasploit 3,477✓ verified onlyrecentpopularrisk
77,772 exploits
VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISK
open ↗VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISK
open ↗VulnCheck XDB
initial-access
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RISK
open ↗Metasploit300
VMware vCenter Secrets Dump
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RISK
open ↗GitHub PoC★ 3
CVE-2022-0185 exploit
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open ↗VulnCheck XDB
local
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open ↗VulnCheck XDB
initial-access
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open ↗GitHub PoC★ 8
Spring Cloud Function SPEL表达式注入漏洞(CVE-2022-22963)
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗GitHub PoC★ 19
The poc for CVE-2022-26809 RCE via RPC will be updated here.
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 32
Detects attempts and successful exploitation of CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
VVeakee/CVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open ↗GitHub PoC★ 7
auduongxuan/CVE-2022-26809
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 27
Remote Code Execution Exploit in the RPC Library
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 1
Proof of Concept for exploiting VMware CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open ↗GitHub PoC★ 68
CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open ↗GitHub PoC
exploitation script tryhackme
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC
VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open ↗GitHub PoC★ 16
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open ↗VulnCheck XDB
initial-access
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
78RISK
open ↗VulnCheck XDB
initial-access
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open ↗GitHub PoC★ 2
AkuCyberSec/CVE-2017-8917-Joomla-370-SQL-Injection
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open ↗VulnCheck XDB
initial-access
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC★ 3
A Zeek detector for CVE-2022-24497.
Windows Network File System Remote Code Execution Vulnerability
60RISK
open ↗GitHub PoC★ 3
A Zeek CVE-2022-24491 detector.
Windows Network File System Remote Code Execution Vulnerability
60RISK
open ↗GitHub PoC★ 3
Easy!Appointments < 1.4.3 - Unauthenticated PII (events) disclosure
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISK
open ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 4
Greenwolf/CVE-2022-1162
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RISK
open ↗GitHub PoC★ 1
corelight/cve-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.