Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
CVE-2023-0159webappsphp19 Mar 2025
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
Exploit-DB
Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
CVE-2023-4220HIGHwebappsphp18 Mar 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
Exploit-DB
openSIS 9.1 - SQLi (Authenticated)
CVE-2024-46626HIGHwebappsphp01 Oct 2024
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
41RISK
open
Exploit-DB
Devika v1 - Path Traversal via 'snapshot_path'
CVE-2024-40422CRITICALwebappspython04 Aug 2024
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISK
open
Exploit-DB
SolarWinds Platform 2024.1 SR1 - Race Condition
CVE-2024-28999MEDIUMwebappsmultiple26 Jun 2024
SolarWinds Platform Race Condition Vulnerability
38RISK
open
Exploit-DB
Wordpress Theme XStore 9.3.8 - SQLi
CVE-2024-33559CRITICALwebappsphp19 May 2024
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
48RISK
open
Exploit-DB
htmlLawed 1.2.5 - Remote Code Execution (RCE)
CVE-2022-35914CRITICALunder attackwebappsphp19 May 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
Exploit-DB
Apache OFBiz 18.12.12 - Directory Traversal
CVE-2024-32113CRITICALunder attackwebappsjava19 May 2024
Apache OFBiz: Path traversal leading to RCE
100RISK
open
Exploit-DB
Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
CVE-2024-34241MEDIUMwebappsphp19 May 2024
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa
33RISK
open
Exploit-DB
Apache mod_proxy_cluster 1.2.6 - Stored XSS
CVE-2023-6710MEDIUMwebappsphp13 May 2024
Mod_cluster/mod_proxy_cluster: stored cross site scripting
33RISK
open
Exploit-DB
Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation
CVE-2024-3400CRITICALunder attackransomwareremotelinux_x86-6421 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
Exploit-DB
Laravel Framework 11 - Credential Leakage
CVE-2024-29291webappsphp21 Apr 2024
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/log
23RISK
open
Exploit-DB
OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
CVE-2023-40279HIGHwebappsphp15 Apr 2024
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page param
41RISK
open
Exploit-DB
OpenClinic GA 5.247.01 - Information Disclosure
CVE-2023-40278HIGHwebappsphp15 Apr 2024
An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the pr
41RISK
open
Exploit-DB
Jenkins 2.441 - Local File Inclusion
CVE-2024-23897CRITICALunder attackransomwarewebappsjava15 Apr 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
Exploit-DB
djangorestframework-simplejwt 5.3.1 - Information Disclosure
CVE-2024-22513MEDIUMwebappspython15 Apr 2024
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web ap
33RISK
open
Exploit-DB
MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
CVE-2024-24747HIGHremotego12 Apr 2024
MinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
53RISK
open
Exploit-DB
GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
CVE-2024-31777CRITICALwebappsphp12 Apr 2024
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RISK
open
Exploit-DB
Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
CVE-2023-6019CRITICALwebappspython12 Apr 2024
Ray Command Injection in cpu_profile Parameter
85RISK
open
Exploit-DB
Axigen < 10.5.7 - Persistent Cross-Site Scripting
CVE-2023-48974CRITICALwebappsphp02 Apr 2024
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges
48RISK
open
Exploit-DB
Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation
CVE-2024-21338HIGHunder attackransomwarelocalwindows02 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
Exploit-DB
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
CVE-2024-24494MEDIUMwebappsphp02 Apr 2024
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via t
38RISK
open
Exploit-DB
Casdoor < v1.331.0 - '/api/set-password' CSRF
CVE-2023-34927webappsgo02 Apr 2024
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISK
open
Exploit-DB
Daily Habit Tracker 1.0 - SQL Injection
CVE-2024-24495CRITICALwebappsphp02 Apr 2024
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit
48RISK
open
Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
CVE-2024-24497webappsphp02 Apr 2024
20RISK
open
Exploit-DB
Daily Habit Tracker 1.0 - Broken Access Control
CVE-2024-24496CRITICALwebappsphp02 Apr 2024
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,
53RISK
open
Exploit-DB
Employee Management System 1.0 - _txtfullname_ and _txtphone_ SQL Injection
CVE-2024-24499webappsphp02 Apr 2024
20RISK
open
Exploit-DB
Gibbon LMS v26.0.00 - SSTI vulnerability
CVE-2024-24724CRITICALwebappsphp02 Apr 2024
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RISK
open
Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
CVE-2024-27356HIGHremotehardware02 Apr 2024
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RISK
open
Exploit-DB
Employee Management System 1.0 - 'admin_id' SQLi
CVE-2024-28595CRITICALwebappsphp20 Mar 2024
SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the ad
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.