Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,056cataloged exploits
35,925CVEs with public exploitation
24,695lab-tested
78,056 exploits
GitHub PoC
Build the struts-2.3.31 (CVE-2017-5638) environment
CVE-2017-5638CRITICALunder attackransomware15 Feb 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
local
CVE-2021-1732HIGHunder attackransomware15 Feb 2022
Windows Win32k Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC4
SQL Injection Vulnerability on PhpIPAM v1.4.4
CVE-2022-2304615 Feb 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open
GitHub PoC51
SAP memory pipes(MPI) desynchronization vulnerability CVE-2022-22536.
CVE-2022-22536CRITICALunder attack15 Feb 2022
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open
GitHub PoC6
r1l4-i3pur1l4/CVE-2022-21882
CVE-2022-21882HIGHunder attackransomware14 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2022-21882HIGHunder attackransomware14 Feb 2022
Win32k Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALunder attack14 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-21311HIGHunder attack14 Feb 2022
SSRF in adminer
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack13 Feb 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware13 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
Python exploit for CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
CVE-2017-891713 Feb 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware12 Feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC17
purple-WL/wordpress-CVE-2022-21661
CVE-2022-21661HIGH12 Feb 2022
SQL injection in WordPress
78RISK
open
GitHub PoC
CVE-2014-1767在win7_x64平台的EXP和分析文章
CVE-2014-176712 Feb 2022
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RISK
open
GitHub PoC3
Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting cooki3 script as the main exploit tools & integration
CVE-2021-44228CRITICALunder attackransomware12 Feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-21661HIGH12 Feb 2022
SQL injection in WordPress
78RISK
open
GitHub PoC1
purple-WL/Jenkins_CVE-2019-1003000
CVE-2019-100300012 Feb 2022
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RISK
open
Exploit-DB
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
CVE-2021-24931webappsphp10 Feb 2022
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack10 Feb 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALunder attack10 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
GitHub PoC2
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows a Local Or Remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.
CVE-2022-2508910 Feb 2022
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RISK
open
GitHub PoC
docker lab setup for kibana-7609
CVE-2019-7609CRITICALunder attack10 Feb 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
Exploit-DB
Hospital Management Startup 1.0 - 'Multiple' SQLi
CVE-2022-23366webappsphp10 Feb 2022
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
23RISK
open
GitHub PoC
puckiestyle/CVE-2022-20699
CVE-2022-20699CRITICALunder attack10 Feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RISK
open
Metasploit300
Strapi CMS Unauthenticated Password Reset
CVE-2019-1881809 Feb 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
Exploit-DB
AtomCMS v2.0 - SQLi
CVE-2022-24223webappsphp09 Feb 2022
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
50RISK
open
Exploit-DB
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
CVE-2021-24901webappsphp08 Feb 2022
Security Audit <= 1.0.0 - Admin+ Stored Cross Site Scripting
23RISK
open
previouspage 612 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.