Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
13,689 exploits
GitHub PoC35
Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others.
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC24
PoC RCE in OpenSSH
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC380
32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC129
MIRROR of the original 32-bit PoC for CVE-2024-6387 "regreSSHion" by 7etsuo/cve-2024-6387-poc
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC9
CosmicSting: critical unauthenticated XXE vulnerability in Adobe Commerce and Magento (CVE-2024-34102)
CVE-2024-34102CRITICALunder attack01 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC
cmsec423/Magento-XXE-CVE-2024-34102
CVE-2024-34102CRITICALunder attack01 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC
Magento XXE
CVE-2024-34102CRITICALunder attack01 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC526
CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
jack0we/CVE-2024-6387
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
passwa11/cve-2024-6387-poc
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
a signal handler race condition in OpenSSH's server (sshd)
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC493
a signal handler race condition in OpenSSH's server (sshd)
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
polkit
CVE-2021-4034HIGHunder attack01 Jul 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
SSHd cve-2024-6387-poc
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
Atreb92/cve-2024-37762
CVE-2024-37762CRITICAL01 Jul 2024
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code executio
48RISK
open
GitHub PoC
Case Study: SSHtranger Things (CVE-2019-6111, CVE-2019-6110) in Cisco SD-WAN
CVE-2019-6111MEDIUM01 Jul 2024
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RISK
open
GitHub PoC
Exploit script showcasing a mixture of CVE-2019-18818 and CVE-2019-19609 for unauthenticated remote code execution in Strapi CMS.
CVE-2019-1881801 Jul 2024
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
GitHub PoC4
This is a proof of concept for the Zyxel vulnerabilities I found. Read the blog :)
CVE-2024-29972CRITICAL30 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RISK
open
GitHub PoC2
CVE-2024-34102 (Magento XXE)
CVE-2024-34102CRITICALunder attack30 Jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.
CVE-2024-22853CRITICAL29 Jun 2024
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote a
48RISK
open
GitHub PoC
CVE-2023-6553 exploit script
CVE-2023-6553CRITICAL29 Jun 2024
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
GitHub PoC1
PavilionQ/CVE-2023-33246-mitigation
CVE-2023-33246CRITICALunder attack29 Jun 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC
phpMyAdmin 2.6.4-pl1 - Directory Traversal
CVE-2005-329929 Jun 2024
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to in
28RISK
open
GitHub PoC
CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware28 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC2
Create lab for CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware28 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
CVE-2024-4040 PoC
CVE-2024-4040CRITICALunder attack28 Jun 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
CVE-2024-21413 PoC
CVE-2024-21413CRITICALunder attack28 Jun 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Modified RCE with a remote shell and logging
CVE-2023-34362CRITICALunder attackransomware28 Jun 2024
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
GitHub PoC
scirusvulgaris/CVE-2017-12617
CVE-2017-12617HIGHunder attack28 Jun 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC48
CosmicSting (CVE-2024-34102)
CVE-2024-34102CRITICALunder attack28 Jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
previouspage 215 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.