Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
NagVis 1.9.33 - Arbitrary File Read
CVE-2022-46945CRITICALwebappsphp16 Apr 2025
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagV
48RISK
open
Exploit-DB
Teedy 1.11 - Account Takeover via Stored Cross-Site Scripting (XSS)
CVE-2024-46278HIGHwebappsmultiple16 Apr 2025
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
41RISK
open
Exploit-DB
Dell EMC iDRAC7/iDRAC8 2.52.52.52 - Remote Code Execution (RCE)
CVE-2018-1207remotehardware16 Apr 2025
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RISK
open
Exploit-DB
phpMyFAQ 3.2.10 - Unintended File Download Triggered by Embedded Frames
CVE-2024-55889MEDIUMwebappsphp16 Apr 2025
phpMyFAQ Vulnerable to Unintended File Download Triggered by Embedded Frames
33RISK
open
Exploit-DB
FLIR AX8 1.46.16 - Remote Command Injection
CVE-2022-37061webappshardware16 Apr 2025
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RISK
open
Exploit-DB
Smart Manager 8.27.0 - Post-Authenticated SQL Injection
CVE-2024-0566HIGHwebappsphp16 Apr 2025
Smart Manager < 8.28.0 - Admin+ SQL Injection
41RISK
open
Exploit-DB
Pymatgen 2024.1 - Remote Code Execution (RCE)
CVE-2024-23346CRITICALremotepython15 Apr 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open
Exploit-DB
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
CVE-2024-6516CRITICALhardwaremultiple15 Apr 2025
Cross Site Scripting XSS
48RISK
open
Exploit-DB
ABB Cylon Aspect 3.08.02 - Cookie User Password Disclosure
CVE-2024-51546HIGHhardwaremultiple15 Apr 2025
Credentails Disclosure
41RISK
open
Exploit-DB
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
CVE-2024-51550CRITICALhardwaremultiple15 Apr 2025
Data Validation / Sanitization
48RISK
open
Exploit-DB
Cacti 1.2.26 - Remote Code Execution (RCE) (Authenticated)
CVE-2024-25641CRITICALwebappsphp15 Apr 2025
Cacti RCE vulnerability when importing packages
85RISK
open
Exploit-DB
Spring Boot common-user-management 0.1 - Remote Code Execution (RCE)
CVE-2024-52302HIGHwebappsjava15 Apr 2025
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
41RISK
open
Exploit-DB
IBMi Navigator 7.5 - HTTP Security Token Bypass
CVE-2024-51464MEDIUMwebappsmultiple15 Apr 2025
IBM i authentication bypass
33RISK
open
Exploit-DB
IBMi Navigator 7.5 - Server Side Request Forgery (SSRF)
CVE-2024-51463MEDIUMwebappsmultiple15 Apr 2025
IBM i server-side request forgery
33RISK
open
Exploit-DB
Really Simple Security 9.1.1.1 - Authentication Bypass
CVE-2024-10924CRITICALwebappsphp15 Apr 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
Exploit-DB
ABB Cylon Aspect 3.08.02 (licenseUpload.php) - Stored Cross-Site Scripting
CVE-2024-6516CRITICALhardwaremultiple15 Apr 2025
Cross Site Scripting XSS
48RISK
open
Exploit-DB
ABB Cylon Aspect 3.08.02 (licenseServerUpdate.php) - Stored Cross-Site Scripting
CVE-2024-6516CRITICALhardwaremultiple15 Apr 2025
Cross Site Scripting XSS
48RISK
open
Exploit-DB
Adapt Authoring Tool 0.11.3 - Remote Command Execution (RCE)
CVE-2024-50672CRITICALwebappsmultiple15 Apr 2025
A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to res
48RISK
open
Exploit-DB
OpenCMS 17.0 - Stored Cross Site Scripting (XSS)
CVE-2024-41947CRITICALwebappsphp15 Apr 2025
XWiki Platform XSS through conflict resolution
48RISK
open
Exploit-DB
ABB Cylon Aspect 3.07.02 (userManagement.php) - Weak Password Policy
CVE-2024-48845CRITICALhardwaremultiple15 Apr 2025
Weak Password Rules/Strength
48RISK
open
Exploit-DB
ABB Cylon Aspect 3.08.02 (escDevicesUpdate.php) - Denial of Service (DOS)
CVE-2024-48844HIGHhardwarephp15 Apr 2025
Denial of Service, DoS
41RISK
open
Exploit-DB
Ivanti Connect Secure 22.7R2.5 - Remote Code Execution (RCE)
CVE-2025-0282CRITICALunder attackransomwareremotemultiple15 Apr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
Exploit-DB
ABB Cylon Aspect 3.08.02 (uploadDb.php) - Remote Code Execution
CVE-2024-48839CRITICALhardwaremultiple15 Apr 2025
Remote Code Execution, RCE
48RISK
open
Exploit-DB
ABB Cylon Aspect 3.08.02 (bbmdUpdate.php) - Remote Code Execution
CVE-2024-48839CRITICALhardwaremultiple15 Apr 2025
Remote Code Execution, RCE
48RISK
open
Exploit-DB
Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
CVE-2019-19245webappsmultiple14 Apr 2025
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[use
23RISK
open
Exploit-DB
GestioIP 3.5.7 - Remote Command Execution (RCE)
CVE-2024-48760CRITICALremotemultiple14 Apr 2025
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke
75RISK
open
Exploit-DB
GestioIP 3.5.7 - Reflected Cross-Site Scripting (Reflected XSS)
CVE-2024-50859MEDIUMremotemultiple14 Apr 2025
The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly forma
33RISK
open
Exploit-DB
GestioIP 3.5.7 - Stored Cross-Site Scripting (Stored XSS)
CVE-2024-50861MEDIUMremotemultiple14 Apr 2025
The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod
33RISK
open
Exploit-DB
OpenPanel 0.3.4 - Directory Traversal
CVE-2024-53537CRITICALwebappsmultiple14 Apr 2025
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager
48RISK
open
Exploit-DB
OpenPanel 0.3.4 - Incorrect Access Control
CVE-2024-53582HIGHwebappsmultiple14 Apr 2025
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec
41RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.