Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
13,689 exploits
GitHub PoC1
poc of git rce using cve-2024-32002
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Repo for testing CVE-2024-32002
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Presentazione per il corsi di sicurezza Informatica sulla vulnerabilità CVE-2024-3094
CVE-2024-3094CRITICAL22 May 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
yuansec/CVE-2024-4323-dos_poc
CVE-2024-4323CRITICAL22 May 2024
Fluent Bit Memory Corruption Vulnerability
53RISK
open
GitHub PoC
This is the main repository for CVE 2024-32002, and requires recursive cloning because it contains the submodels necessary for execution.
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
1mxml/CVE-2024-32002-poc
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
bfengj/CVE-2024-32002-hook
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC2
bfengj/CVE-2024-32002-Exploit
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
CVE-2024-32002-hook
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC4
The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based clients and servers using a version of FreeRDP prior to version 3.5.0 or 2.11.6 are vulnerable to out-of-bounds reading12. Versions 3.5.0 and 2.11.6 correct the problem
CVE-2024-32459CRITICAL22 May 2024
FreeRDP Out-Of-Bounds Read in ncrush_decompress
48RISK
open
GitHub PoC
Proof Of Concept for the CVE-2016-10033 (PHPMailer)
CVE-2016-10033CRITICALunder attack22 May 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC4
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
CVE-2024-4367MEDIUM22 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC11
YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js
CVE-2024-4367MEDIUM22 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
This script checks if a target host is vulnerable to CVE-2023-34992 by sending a crafted payload to the FortiSIEM appliance. It then analyzes the response to determine if the host is vulnerable.
CVE-2023-34992CRITICAL21 May 2024
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISK
open
GitHub PoC3
Patch your D-Link device affected by CVE-2024-3272
CVE-2024-3272CRITICALunder attack21 May 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
100RISK
open
GitHub PoC2
CVE-2019-3396 Memshell for Behinder
CVE-2019-3396CRITICALunder attackransomware21 May 2024
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
CVE-2024-32002 hook POC
CVE-2024-32002CRITICAL21 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Securenetology/CVE-2013-3900
CVE-2013-3900MEDIUMunder attack21 May 2024
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC
Este script está creado para mostar usuarios de DVR, VULNERABILIDAD (CVE-2018-9995)
CVE-2018-999521 May 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC1
Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.
CVE-2024-4323CRITICAL21 May 2024
Fluent Bit Memory Corruption Vulnerability
53RISK
open
GitHub PoC6
Este script demuestra cómo explotar la vulnerabilidad CVE-2024-32002 para obtener una reverse shell, proporcionando acceso remoto al sistema afectado. Úselo con precaución en entornos controlados y solo con fines educativos o de pruebas de seguridad.
CVE-2024-32002CRITICAL21 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
CVE-2024-32002 POC
CVE-2024-32002CRITICAL21 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
fabdotnet/CVE-2023-27100
CVE-2023-27100CRITICAL20 May 2024
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open
GitHub PoC15
This proof-of-concept script demonstrates how to exploit CVE-2024-4323, a memory corruption vulnerability in Fluent Bit, enabling remote code execution.
CVE-2024-4323CRITICAL20 May 2024
Fluent Bit Memory Corruption Vulnerability
53RISK
open
GitHub PoC140
Time Based SQL Injection in Zabbix Server Audit Log --> RCE
CVE-2024-22120CRITICAL20 May 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISK
open
GitHub PoC1
CrackerCat/CVE-2024-32002_EXP
CVE-2024-32002CRITICAL20 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC57
CVE-2024-4367 arbitrary js execution in pdf js
CVE-2024-4367MEDIUM20 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC3
jweny/CVE-2024-32002_EXP
CVE-2024-32002CRITICAL20 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC203
CVE-2024-4367 & CVE-2024-34342 Proof of Concept
CVE-2024-4367MEDIUM20 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC11
Unlock your Huawei device with ADB (CVE-2019-2215)
CVE-2019-2215HIGHunder attack20 May 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
previouspage 225 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.