Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
Typecho 1.3.0 - Race Condition
CVE-2024-35539MEDIUMwebappsphp10 Apr 2025
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerabil
33RISK
open
Exploit-DB
K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
CVE-2024-36424MEDIUMremotemultiple10 Apr 2025
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of
33RISK
open
Exploit-DB
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
CVE-2024-7815MEDIUMwebappsphp10 Apr 2025
CodeAstro Online Railway Reservation System Update Employee Page admin-update-employee.php cross site scripting
33RISK
open
Exploit-DB
Feng Office 3.11.1.2 - SQL Injection
CVE-2024-6039MEDIUMwebappsphp10 Apr 2025
Feng Office Workspaces sql injection
33RISK
open
Exploit-DB
Centron 19.04 - Remote Code Execution (RCE)
CVE-2019-13024webappsphp10 Apr 2025
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RISK
open
Exploit-DB
AquilaCMS 1.409.20 - Remote Command Execution (RCE)
CVE-2024-48573CRITICALwebappsphp10 Apr 2025
A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and admin
48RISK
open
Exploit-DB
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
CVE-2024-20419CRITICALwebappsmultiple10 Apr 2025
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RISK
open
Exploit-DB
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
CVE-2024-38944CRITICALwebappsmultiple09 Apr 2025
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the
48RISK
open
Exploit-DBVexDay Proof
DocsGPT 0.12.0 - Remote Code Execution
CVE-2025-0868CRITICALwebappspython09 Apr 2025
Remote Code Execution in DocsGPT
68RISK
open
Exploit-DB
Artica Proxy 4.50 - Remote Code Execution (RCE)
CVE-2024-2054CRITICALwebappsphp09 Apr 2025
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RISK
open
Exploit-DB
ChurchCRM 5.9.1 - SQL Injection
CVE-2024-39304HIGHwebappsphp09 Apr 2025
ChurchCRM SQL Injection Vulnerability
41RISK
open
Exploit-DB
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
CVE-2024-39143MEDIUMwebappsphp09 Apr 2025
A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to crea
33RISK
open
Exploit-DB
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
CVE-2024-6244HIGHwebappsphp09 Apr 2025
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RISK
open
Exploit-DB
Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
CVE-2024-24409HIGHwebappsmultiple09 Apr 2025
Privilege Escalation
41RISK
open
Exploit-DB
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
CVE-2024-27348CRITICALunder attackwebappsjava09 Apr 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
Exploit-DB
InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
CVE-2024-30896CRITICALremotemultiple08 Apr 2025
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut
48RISK
open
Exploit-DB
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
CVE-2019-15949HIGHunder attackwebappsmultiple08 Apr 2025
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISK
open
Exploit-DB
Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE)
CVE-2024-23922MEDIUMremotemultiple08 Apr 2025
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability
33RISK
open
Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
CVE-2020-7656webappsmultiple08 Apr 2025
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re
23RISK
open
Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
CVE-2019-11358webappsmultiple08 Apr 2025
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
Exploit-DB
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
CVE-2024-56902HIGHwebappsmultiple08 Apr 2025
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
46RISK
open
Exploit-DB
XWiki Platform 15.10.10 - Remote Code Execution
CVE-2025-24893CRITICALunder attackwebappsmultiple07 Apr 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
Exploit-DB
YesWiki 4.5.1 - Unauthenticated Path Traversal
CVE-2025-31131HIGHwebappsmultiple07 Apr 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RISK
open
Exploit-DB
Apache Tomcat 11.0.3 - Remote Code Execution
CVE-2025-24813CRITICALunder attackwebappsmultiple07 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Exploit-DB
Watcharr 1.43.0 - Remote Code Execution (RCE)
CVE-2024-48827HIGHwebappsmultiple06 Apr 2025
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
41RISK
open
Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
CVE-2024-9458MEDIUMwebappsphp06 Apr 2025
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RISK
open
Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
CVE-2024-8856CRITICALwebappsphp06 Apr 2025
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
CVE-2024-30269MEDIUMwebappsjava06 Apr 2025
DataEase has database configuration information exposure vulnerability
53RISK
open
Exploit-DB
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
CVE-2024-5910CRITICALunder attackwebappsmultiple06 Apr 2025
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISK
open
Exploit-DB
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
CVE-2025-2294CRITICALwebappsmultiple05 Apr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.