Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
13,668 exploits
GitHub PoC
a-roshbaik/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware24 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC2
Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode exploitation technique.
CVE-2023-38831HIGHunder attackransomware23 Jul 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
CERTologists/EXPLOITING-CVE-2024-27956
CVE-2024-27956CRITICAL23 Jul 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC23
Updated Exploit - pfBlockerNG <= 2.1.4_26 Unauth RCE (CVE-2022-31814)
CVE-2022-31814CRITICAL23 Jul 2024
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC
Tool for checking Nginx CVE-2013-2028
CVE-2013-202823 Jul 2024
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RISK
open
GitHub PoC
a test repository for CVE-2018-17456's PoC
CVE-2018-1745622 Jul 2024
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
GitHub PoC
Hello everyone, I am sharing a modified script from CVE-2024-24919 which can extract paths categorized as critical.
CVE-2024-24919HIGHunder attackransomware22 Jul 2024
Information disclosure
100RISK
open
GitHub PoC
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised users.
CVE-2021-43798HIGHunder attack22 Jul 2024
Grafana path traversal
100RISK
open
GitHub PoC
CVE 2023-22515
CVE-2023-22515CRITICALunder attackransomware21 Jul 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
HPT-Intern-Task-Submission/CVE-2024-27198
CVE-2024-27198CRITICALunder attackransomware20 Jul 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC
TSY244/CVE-2024-32002-git-rce
CVE-2024-32002CRITICAL20 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Educational exploit for CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware20 Jul 2024
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
TSY244/CVE-2024-32002-git-rce-father-poc
CVE-2024-32002CRITICAL20 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Wytchwulf/CVE-2015-1397-Magento-Shoplift
CVE-2015-139719 Jul 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISK
open
GitHub PoC
CVE-2022-37706-Enlightenment v0.25.3 - Privilege escalation
CVE-2022-37706HIGH19 Jul 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open
GitHub PoC2
Proof Of Concept for CVE-2024-1874
CVE-2024-1874CRITICAL18 Jul 2024
Command injection via array-ish $command parameter of proc_open()
60RISK
open
GitHub PoC4
Vulnerability checking tool via Nmap Scripting Engine
CVE-2023-22515CRITICALunder attackransomware18 Jul 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC43
geoserver CVE-2024-36401漏洞利用工具
CVE-2024-36401CRITICALunder attack17 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC1
Script para eliminar vulnerabilidad de openssh de ubuntu 22.04 LTS
CVE-2023-38408CRITICAL17 Jul 2024
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC3
Exploit for CVE-2024-31989.
CVE-2024-31989CRITICAL17 Jul 2024
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache
48RISK
open
GitHub PoC
khanhtranngoccva/cve-2023-38831-poc
CVE-2023-38831HIGHunder attackransomware16 Jul 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC1
Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases
CVE-2024-4879CRITICALunder attack16 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC
Automated PHP remote code execution scanner for CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware16 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Laravel Debug Mode and Payload
CVE-2021-3129CRITICALunder attackransomware16 Jul 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
On October 4, 2021, Apache HTTP Server Project released Security advisory on a Path traversal and File disclosure vulnerability in Apache HTTP Server 2.4.49 and 2.4.50 tracked as CVE-2021-41773 and CVE-2021-42013. In the advisory, Apache also highlighted “the issue is known to be exploited in the wild” and later it was identified that the vulnerabi
CVE-2021-42013CRITICALunder attackransomware16 Jul 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC2
OpenSSH RCE Massive Vulnerable Scanner
CVE-2024-6387HIGH15 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC525
Kernel exploit for Xbox SystemOS using CVE-2024-30088
CVE-2024-30088HIGHunder attackransomware15 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
LMS Chamilo 1.11.24 CVE-2023-4220 Exploit
CVE-2023-4220HIGH15 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC1
Phantom-IN/CVE-2024-34102
CVE-2024-34102CRITICALunder attack14 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC1
Prueba de concepto para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).
CVE-2014-6271CRITICALunder attack14 Jul 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
previouspage 209 / 456next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.