Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
13,689 exploits
GitHub PoC1
A Simple Exploit Code(POC) to Automate CVE-2024–24919
CVE-2024-24919HIGHunder attackransomware06 Jun 2024
Information disclosure
100RISK
open
GitHub PoC
sql延时注入poc
CVE-2024-32640CRITICAL06 Jun 2024
MasaCMS SQL Injection vulnerability
85RISK
open
GitHub PoC
A script to exploit CVE-2020-1472 (Zerologon)
CVE-2020-1472MEDIUMunder attackransomware06 Jun 2024
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
NanoWraith/CVE-2024-5084
CVE-2024-5084CRITICAL06 Jun 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
GitHub PoC4
conan-sudo/CVE-2019-14974-bypass
CVE-2019-1497406 Jun 2024
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
50RISK
open
GitHub PoC
muhammad1596/CVE-2022-0847-DirtyPipe-Exploits
CVE-2022-0847HIGHunder attack06 Jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC1
Oracle WebLogic Server (LFI)
CVE-2022-21371HIGH05 Jun 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
GitHub PoC9
CVE-2024-4956 Python exploitation utility
CVE-2024-4956HIGH05 Jun 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC26
Sk1dr0wz/CVE-2024-4358_Mass_Exploit
CVE-2024-4358CRITICALunder attack05 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
GitHub PoC
This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps.
CVE-2023-22515CRITICALunder attackransomware05 Jun 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit
CVE-2017-891705 Jun 2024
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
GitHub PoC
CVE-2021-1675/CVE-2021-34527 PrintNightmare & CVE-2020-0668
CVE-2021-1675HIGHunder attackransomware05 Jun 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
junnythemarksman/CVE-2023-30547
CVE-2023-30547CRITICAL04 Jun 2024
Sandbox Escape in vm2
70RISK
open
GitHub PoC5
An Vulnerability detection and Exploitation tool for CVE-2024-4358
CVE-2024-4358CRITICALunder attack04 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
GitHub PoC1
0xans/CVE-2024-24919
CVE-2024-24919HIGHunder attackransomware04 Jun 2024
Information disclosure
100RISK
open
GitHub PoC
Harydhk7/CVE-2024-4358
CVE-2024-4358CRITICALunder attack04 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
GitHub PoC2
Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16
CVE-2024-21111HIGH04 Jun 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISK
open
GitHub PoC1
muhammad1596/CVE-2022-0847-dirty-pipe-checker
CVE-2022-0847HIGHunder attack04 Jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
Tim-Hoekstra/CVE-2024-24919
CVE-2024-24919HIGHunder attackransomware04 Jun 2024
Information disclosure
100RISK
open
GitHub PoC1
CVE-2023-51518: Preauthenticated Java Deserialization via JMX in Apache James
CVE-2023-51518CRITICAL03 Jun 2024
Apache James server: Privilege escalation via JMX pre-authentication deserialisation
48RISK
open
GitHub PoC3
Sonatype Nexus Repository Manager 3 (LFI)
CVE-2024-4956HIGH03 Jun 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC11
0nin0hanz0/CVE-2024-24919-PoC
CVE-2024-24919HIGHunder attackransomware03 Jun 2024
Information disclosure
100RISK
open
GitHub PoC1
birdlex/cve-2024-24919-checker
CVE-2024-24919HIGHunder attackransomware03 Jun 2024
Information disclosure
100RISK
open
GitHub PoC79
Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)
CVE-2024-4358CRITICALunder attack03 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
GitHub PoC4
Nmap script to check vulnerability CVE-2024-24919
CVE-2024-24919HIGHunder attackransomware03 Jun 2024
Information disclosure
100RISK
open
GitHub PoC3
CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.
CVE-2024-24919HIGHunder attackransomware03 Jun 2024
Information disclosure
100RISK
open
GitHub PoC
Exploit created by nu11secur1ty (https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2022-37706)
CVE-2022-37706HIGH03 Jun 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open
GitHub PoC19
Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit
CVE-2024-27348CRITICALunder attack03 Jun 2024
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
GitHub PoC2
kevcooper/CVE-2024-1086-checker
CVE-2024-1086HIGHunder attackransomware03 Jun 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC27
Apache OFBIZ Path traversal leading to RCE POC[CVE-2024-32113 & CVE-2024-36104]
CVE-2024-32113CRITICALunder attack03 Jun 2024
Apache OFBiz: Path traversal leading to RCE
100RISK
open
previouspage 221 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.