Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
13,654 exploits
GitHub PoC3
Analysis , Demo exploit and poc about CVE-2024-37084
CVE-2024-37084CRITICAL10 Sep 2024
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISK
open
GitHub PoC1
KaoXx/CVE-2022-37706
CVE-2022-37706HIGH10 Sep 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open
GitHub PoC
carradolly/CVE-2015-8660
CVE-2015-866010 Sep 2024
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISK
open
GitHub PoC1
Artemisxxx37/OverlayFS-PrivEsc-CVE-2022-0944
CVE-2022-0944CRITICAL10 Sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC
Python3 toolkit update
CVE-2017-0199HIGHunder attackransomware10 Sep 2024
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC1
Scanning CVE-2024-4577 vulnerability with a url list.
CVE-2024-4577CRITICALunder attackransomware10 Sep 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC9
0xRoqeeb/sqlpad-rce-exploit-CVE-2022-0944
CVE-2022-0944CRITICAL10 Sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC
CVE-2024-23897 분석
CVE-2024-23897CRITICALunder attackransomware09 Sep 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC5
SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])
CVE-2022-0944CRITICAL09 Sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC1
CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp
CVE-2024-28000CRITICAL09 Sep 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open
GitHub PoC
PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: https://huntr.com/bounties/46630727-d923-4444-a421-537ecd63e7fb
CVE-2022-0944CRITICAL09 Sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC4
CVE-2018-0834 full code exec
CVE-2018-083409 Sep 2024
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISK
open
GitHub PoC
LucasOneZ/CVE-2023-4966
CVE-2023-4966CRITICALunder attackransomware09 Sep 2024
Unauthenticated sensitive information disclosure
100RISK
open
GitHub PoC4
A proof of concept of the LFI vulnerability on aiohttp 3.9.1
CVE-2024-23334MEDIUM08 Sep 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC7
A proof of concept exploit for SQLPad RCE (CVE-2022-0944).
CVE-2022-0944CRITICAL08 Sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC
quick powershell script to fix cve-2024-38063
CVE-2024-38063CRITICAL07 Sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC5
🔥 CVE-2024-44849 Exploit
CVE-2024-44849CRITICAL07 Sep 2024
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RISK
open
GitHub PoC
LiteSpeed Unauthorized Account Takeover
CVE-2024-44000CRITICAL06 Sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
GitHub PoC16
CVE-2024-44000 is a vulnerability in the LiteSpeed Cache plugin, a popular WordPress plugin. This vulnerability affects session management in LiteSpeed Cache, allowing attackers to gain unauthorized access to sensitive data.
CVE-2024-44000CRITICAL06 Sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
GitHub PoC
deskfiler 1.2.3 Open Redirect exploit
CVE-2024-25291CRITICAL06 Sep 2024
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
48RISK
open
GitHub PoC
nteract 0.28.0 open redirect to RCE exploit
CVE-2024-22891CRITICAL06 Sep 2024
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
48RISK
open
GitHub PoC
test POC for CVE-2019-10149
CVE-2019-10149CRITICALunder attack06 Sep 2024
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC2
XSS to RCE in RenderTune v1.1.4 exploit
CVE-2024-25292CRITICAL06 Sep 2024
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML
48RISK
open
GitHub PoC16
SPIP BigUp Plugin Unauthenticated RCE
CVE-2024-8517CRITICAL06 Sep 2024
SPIP Bigup Multipart File Upload OS Command Injection
85RISK
open
GitHub PoC6
fru1ts/CVE-2024-44902
CVE-2024-44902CRITICAL05 Sep 2024
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RISK
open
GitHub PoC5
Research and PoC for CVE-2024-6386
CVE-2024-6386CRITICAL05 Sep 2024
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
53RISK
open
GitHub PoC
bryanqb07/CVE-2023-32315
CVE-2023-32315HIGHunder attack05 Sep 2024
Openfire administration console authentication bypass
100RISK
open
GitHub PoC12
Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)
CVE-2024-28987CRITICALunder attack05 Sep 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open
GitHub PoC1
This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.
CVE-2017-5638CRITICALunder attackransomware04 Sep 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC4
Masamuneee/CVE-2024-4367-Analysis
CVE-2024-4367MEDIUM04 Sep 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
previouspage 201 / 456next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.