Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
13,654 exploits
GitHub PoC2
CVE-2024-55215
CVE-2024-55215CRITICAL28 Nov 2024
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter
48RISK
open
GitHub PoC1
letsr00t/CVE-2023-2163
CVE-2023-2163CRITICAL27 Nov 2024
Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation
48RISK
open
GitHub PoC
dlink vulnerability thing in python and rust
CVE-2024-10914CRITICAL27 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC2
CVE-2024-36401 (GeoServer Remote Code Execution)
CVE-2024-36401CRITICALunder attack27 Nov 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC6
Bypass del MFA en WordPress con el plugin Really Simple Security instalado entre las versiones 9.0.0 – 9.1.1.1.
CVE-2024-10924CRITICAL27 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC7
A PoC exploit for CVE-2024-10914 - D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL27 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
0xDTC/Magento-eCommerce-RCE-CVE-2015-1397
CVE-2015-139727 Nov 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISK
open
GitHub PoC96
synacktiv/CVE-2024-43468
CVE-2024-43468CRITICALunder attack26 Nov 2024
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RISK
open
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2021-36260CRITICALunder attack26 Nov 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC1
Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability
CVE-2012-183126 Nov 2024
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RISK
open
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2017-7921CRITICALunder attack26 Nov 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC3
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation
CVE-2024-10542CRITICAL26 Nov 2024
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
53RISK
open
GitHub PoC1
Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible
CVE-2014-6271CRITICALunder attack26 Nov 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2022-28171HIGH26 Nov 2024
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RISK
open
GitHub PoC
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-52380CRITICAL25 Nov 2024
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
Working Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.
CVE-2022-0847HIGHunder attack25 Nov 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you cannot upgrade Magento or cannot apply the official patches, try this one.
CVE-2022-24086CRITICALunder attack25 Nov 2024
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
GitHub PoC
Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection
CVE-2024-52430CRITICAL25 Nov 2024
WordPress Lis Video Gallery plugin <= 0.2.1 - PHP Object Injection vulnerability
48RISK
open
GitHub PoC
WolffCorentin/CVE-2019-1663-Binary-Analysis
CVE-2019-1663CRITICAL24 Nov 2024
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open
GitHub PoC
YassDEV221608/CVE-2024-6387
CVE-2024-6387HIGH24 Nov 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
francescobrina/hfs-cve-2014-6287-exploit
CVE-2014-6287CRITICALunder attack24 Nov 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC1
Xss injection, WonderCMS 3.2.0 -3.4.2
CVE-2023-41425MEDIUM24 Nov 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC1
Remote Command Execution into shell from a vulnerable exim service.
CVE-2019-10149CRITICALunder attack24 Nov 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC24
CVE-2024-35250 的 Beacon Object File (BOF) 实现。
CVE-2024-35250HIGHunder attack23 Nov 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
GitHub PoC1
CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。
CVE-2023-20198CRITICALunder attack23 Nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC1
CVE-2024-32002 是 Git 中的一个严重漏洞,允许攻击者在用户执行 git clone 操作时远程执行任意代码(RCE)。
CVE-2024-32002CRITICAL23 Nov 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC1
BohemianHacks/CVE-2024-21534-poc
CVE-2024-21534CRITICAL23 Nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RISK
open
GitHub PoC
0-Gram/CVE-2022-41040
CVE-2022-41040HIGHunder attackransomware23 Nov 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection
CVE-2024-52433CRITICAL22 Nov 2024
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RISK
open
GitHub PoC
Broken Authentication in Wordpress plugin (Wawp Plugin < 3.0.18)
CVE-2024-52475CRITICAL22 Nov 2024
WordPress Wawp plugin < 3.0.18 - Account Takeover vulnerability
48RISK
open
previouspage 190 / 456next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.