Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
77,813 exploits
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware02 Mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
Xerte 3.10.3 - Directory Traversal (Authenticated)
CVE-2021-44665webappsphp02 Mar 2022
A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via
23RISK
open
Exploit-DB
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
CVE-2021-46387webappsmultiple02 Mar 2022
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RISK
open
Exploit-DB
Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-44664webappsphp02 Mar 2022
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupl
28RISK
open
GitHub PoC
Tools for get offsets and adding patch for support i386
CVE-2018-100000101 Mar 2022
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
VulnCheck XDB
local
CVE-2018-100000101 Mar 2022
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RISK
open
GitHub PoC15
Zabbix - SAML SSO Authentication Bypass
CVE-2022-23131CRITICALunder attack28 Feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-24086CRITICALunder attack28 Feb 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALunder attack28 Feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC1
Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration
CVE-2019-2215HIGHunder attack28 Feb 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware28 Feb 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
local
CVE-2022-0492HIGHunder attack28 Feb 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
GitHub PoC
This script is intended to validate Apache Struts 2 vulnerability (CVE-2017-5638), AKA Struts-Shock.
CVE-2017-5638CRITICALunder attackransomware28 Feb 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Metasploit300
Wordpress BookingPress bookingpress_front_get_category_services SQLi
CVE-2022-073928 Feb 2022
BookingPress < 1.0.11 - Unauthenticated SQL Injection
30RISK
open
GitHub PoC
CVE-2022-24086 RCE
CVE-2022-24086CRITICALunder attack28 Feb 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
Exploit-DB
Casdoor 1.13.0 - SQL Injection (Unauthenticated)
CVE-2022-24124webappsmultiple28 Feb 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware28 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack28 Feb 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC47
Test whether a container environment is vulnerable to container escapes via CVE-2022-0492
CVE-2022-0492HIGHunder attack28 Feb 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RISK
open
GitHub PoC1
Fa1c0n35/zabbix-cve-2022-23131
CVE-2022-23131CRITICALunder attack27 Feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware27 Feb 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
skentagon/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware27 Feb 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit600
Webmin File Manager RCE
CVE-2022-0824HIGH26 Feb 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RISK
open
GitHub PoC303
PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"
CVE-2022-21971HIGHunder attack26 Feb 2022
Windows Runtime Remote Code Execution Vulnerability
83RISK
open
VulnCheck XDB
client-side
CVE-2022-21971HIGHunder attack26 Feb 2022
Windows Runtime Remote Code Execution Vulnerability
83RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack25 Feb 2022
Grafana path traversal
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-2506025 Feb 2022
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_sta
35RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack25 Feb 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware25 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC8
POC for CVE-2022-24124
CVE-2022-2412425 Feb 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RISK
open
previouspage 604 / 2,594next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.