Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware23 Nov 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack23 Nov 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attack23 Nov 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware23 Nov 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2024-7965HIGHunder attack22 Nov 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-27130HIGH22 Nov 2024
QTS, QuTS hero
53RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH22 Nov 2024
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALunder attack22 Nov 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-20198CRITICALunder attack22 Nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-25065MEDIUM22 Nov 2024
OpenNetAdmin os command injection
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack22 Nov 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack22 Nov 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-29442HIGH22 Nov 2024
Authentication bypass
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALunder attack22 Nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864622 Nov 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware21 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL20 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware20 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware20 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
local
CVE-2024-49039HIGHunder attackransomware19 Nov 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware19 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
infoleak
CVE-2018-376019 Nov 2024
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-3722HIGH19 Nov 2024
Avaya Aura Device Services Remote Code Execution
56RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware19 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
previouspage 106 / 273next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.