Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
78,056 exploits
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL23 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC28
CVE-2022-21907 Vulnerability PoC
CVE-2022-21907CRITICAL23 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
Strapi CMS 3.0.0-beta.17.4 - Unauthenticated Remote Code Execution (CVE-2019-18818, CVE-2019-19609)
CVE-2019-1960923 Jan 2022
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
GitHub PoC1
jcarabantes/CVE-2022-23046
CVE-2022-2304622 Jan 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RISK
open
Metasploit600
Apache Couchdb Erlang RCE
CVE-2022-24706CRITICALunder attack21 Jan 2022
Remote Code Execution Vulnerability in Packaging
100RISK
open
GitHub PoC5
test 反向辣鸡数据投放 CVE-2022-23305 工具 利用 教程 Exploit POC
CVE-2022-23305CRITICAL21 Jan 2022
SQL injection in JDBC Appender in Apache Log4j V1
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-24489CRITICALunder attack20 Jan 2022
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack19 Jan 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
local
CVE-2022-0185HIGHunder attack19 Jan 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
GitHub PoC24
💀 Linux local root exploit for CVE-2018-18955
CVE-2018-1895519 Jan 2022
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RISK
open
GitHub PoC375
CVE-2022-0185
CVE-2022-0185HIGHunder attack19 Jan 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
Metasploit600
Oracle Access Manager unauthenticated Remote Code Execution
CVE-2021-35587CRITICALunder attack19 Jan 2022
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-21661HIGH18 Jan 2022
SQL injection in WordPress
78RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack18 Jan 2022
Grafana path traversal
100RISK
open
VulnCheck XDB
client-side
CVE-2020-1472MEDIUMunder attackransomware18 Jan 2022
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack18 Jan 2022
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure
CVE-2022-23178webappshardware18 Jan 2022
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware18 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC360
HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907
CVE-2022-21907CRITICAL17 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC83
Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers
CVE-2022-21907CRITICAL17 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
KasunPriyashan/Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability
CVE-2016-5195HIGHunder attack17 Jan 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL17 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial
CVE-2022-21907CRITICAL17 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL17 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
A Java application intentionally vulnerable to CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware16 Jan 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-42237CRITICALunder attackransomware16 Jan 2022
Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware15 Jan 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC26
CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and protection: Powershell. Demonstration: Youtube.
CVE-2022-21907CRITICAL15 Jan 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2021-32648HIGHunder attack14 Jan 2022
Account Takeover in Octobercms
100RISK
open
GitHub PoC1
cf8-upload.py | CVE-2009-2265
CVE-2009-226514 Jan 2022
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
previouspage 619 / 2,602next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.