Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,505cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
13,627 exploits
GitHub PoC1
webmin or minisever RCE
CVE-2019-15107CRITICALunder attackransomware19 Dec 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC2
dustblessnotdust/CVE-2024-53677-S2-067-thread
CVE-2024-53677CRITICAL18 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC
CVE-2023-4966-exploit
CVE-2023-4966CRITICALunder attackransomware18 Dec 2024
Unauthenticated sensitive information disclosure
100RISK
open
GitHub PoC4
v3153/CVE-2024-50379-POC
CVE-2024-50379CRITICAL18 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
GitHub PoC1
Adobe ColdFusion 8 - Remote Command Execution (RCE)
CVE-2009-226518 Dec 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
GitHub PoC3
yangyanglo/CVE-2024-53677
CVE-2024-53677CRITICAL17 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC3
A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.
CVE-2024-53677CRITICAL17 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC1
An example project that showcases golang code vulnerable to CVE-2024-45337
CVE-2024-45337CRITICAL17 Dec 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISK
open
GitHub PoC6
Proof of concept (POC) for CVE-2024-45337
CVE-2024-45337CRITICAL17 Dec 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISK
open
GitHub PoC21
LLfam/CVE-2024-1086
CVE-2024-1086HIGHunder attackransomware16 Dec 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC
DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection
CVE-2024-50507CRITICAL16 Dec 2024
WordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
48RISK
open
GitHub PoC14
A short scraper looking for a POC of CVE-2024-49112
CVE-2024-49112CRITICAL16 Dec 2024
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
redspy-sec/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware16 Dec 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
The EXP/POC of CVE-2019-12725
CVE-2019-1272516 Dec 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
GitHub PoC
Rahul-Thakur7/CVE-2023-21554
CVE-2023-21554CRITICAL16 Dec 2024
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open
GitHub PoC
t0mmy4/CVE-2019-12725-modified-exp
CVE-2019-1272516 Dec 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
GitHub PoC4
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised users.
CVE-2021-43798HIGHunder attack14 Dec 2024
Grafana path traversal
100RISK
open
GitHub PoC
Improved version of PikaChu CVE
CVE-2017-12617HIGHunder attack13 Dec 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC
sudlit/CVE-2023-40028
CVE-2023-40028MEDIUM13 Dec 2024
Arbitrary file read via symlinks in Ghost
45RISK
open
GitHub PoC
tlavi00/CVE-2018-7750
CVE-2018-775013 Dec 2024
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISK
open
GitHub PoC
CVE to CTF FP
CVE-2022-22963CRITICALunder attack13 Dec 2024
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
GitHub PoC
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
CVE-2024-9290CRITICAL13 Dec 2024
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RISK
open
GitHub PoC4
666asd/CVE-2024-23653
CVE-2024-23653CRITICAL13 Dec 2024
BuildKit interactive containers API does not validate entitlements check
48RISK
open
GitHub PoC8
CVE-2024-55875 | GHSA-7mj5-hjjj-8rgw | http4k first CVE
CVE-2024-55875CRITICAL13 Dec 2024
http4k has a potential XXE (XML External Entity Injection) vulnerability
48RISK
open
GitHub PoC96
A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises from flaws in the file upload logic, which can be exploited to perform path traversal and malicious file uploads.
CVE-2024-53677CRITICAL13 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC
writeup cve-2024-42327
CVE-2024-42327CRITICAL12 Dec 2024
SQL injection in user.get API
70RISK
open
GitHub PoC4
exploit CVE-2024-38475(mod_rewrite weakness with filesystem path matching)
CVE-2024-38475CRITICALunder attack12 Dec 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
GitHub PoC13
CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system.
CVE-2023-40028MEDIUM12 Dec 2024
Arbitrary file read via symlinks in Ghost
45RISK
open
GitHub PoC
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
CVE-2024-10124CRITICAL12 Dec 2024
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
60RISK
open
GitHub PoC9
s2-067(CVE-2024-53677)
CVE-2024-53677CRITICAL12 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
previouspage 186 / 455next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.