Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
13,689 exploits
GitHub PoC★ 4
CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open ↗GitHub PoC★ 1
OpenSSH vulnerability CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
Burp Extension to test for CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC
ThinkAdmin v5 v6 任意文件读取漏洞利用,可自定义字典爆破
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISK
open ↗GitHub PoC
CVE-2023–4220 Exploit
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC★ 8
Perform with massive Wordpress SQLI 2 RCE
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC
Examining the phases of an attack using “Dragonfish's Elise Malware”, specifically, exploring the exploitation of vulnerability CVE-2017-11882.
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗GitHub PoC★ 3
This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware blocks HTTP requests containing specific patterns, and the vulnerability checker tests for and exploits the Apache Struts 2 vulnerability (CVE-2017-5638).
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 1
Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open ↗GitHub PoC
year 2 semester 1 Systems and Network Programming Assignment
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open ↗GitHub PoC★ 3
Guardian Code: A Script to Uncover CVE-2024-5274 Vulnerabilities
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
76RISK
open ↗GitHub PoC
year 2 semester 1 Systems and Network Programming Assignment
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISK
open ↗GitHub PoC
DimaMend/cve-2024-6387-poc
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC★ 102
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
dgourillon/mitigate-CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
regreSSHion is a security tool designed to test for vulnerabilities related to CVE-2024-6387, specifically focusing on SSH and remote access exploitation.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
This Rust Code is designed to check SSH servers for the CVE-2024-6387 vulnerability
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
foudadev/CVE-2007-2447
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗GitHub PoC★ 7
alperenugurlu/CVE-2024-3596-Detector
RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.
53RISK
open ↗GitHub PoC
PoC for CVE-2023-4220 - Chamilo LMS - Unauthenticated File Upload in BigUpload
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC★ 11
Exploit for CVE-2024-4883
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
60RISK
open ↗GitHub PoC★ 5
This is an Exploit for Unrestricted file upload in big file upload functionality in Chamilo-LMS for this location "/main/inc/lib/javascript/bigupload/inc/bigUpload.php" in Chamilo LMS <= v1.11.24, and Attackers can obtain remote code execution via uploading of web shell.
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC★ 17
Exploit for CVE-2024-4885
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 186
Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
Chef Inspec profile for checking regreSSHion vulnerability CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
poc for CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC★ 4
PIN-based Authentication Bypass vulnerability in Kaiten
A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism
48RISK
open ↗GitHub PoC
This is a exploit for CVE-2007-2447; Vulnerable SMB
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗GitHub PoC
sysonlai/CVE-2024-32002-hook
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.