Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
13,705 exploits
GitHub PoC
A check program for CVE-2024-3400, Palo Alto PAN-OS unauthenticated command injection vulnerability. Palo Alto 防火墙 PAN-OS 远程命令注入检测程序。
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
Have we not learnt from HoneyPoC?
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC9
Global Protec Palo Alto File Write Exploit
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC34
CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
LeopoldSkell/CVE-2024-3273
CVE-2024-3273HIGHunder attack16 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC2
CONDITIONBLACK/CVE-2024-3400-POC
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC8
CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC15
Chocapikk/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC161
CVE-2024-3400 Palo Alto OS Command Injection
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
LoanVitor/CVE-2024-3400-
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC92
CVE-2024-3400-RCE
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
A simple bash script to check for evidence of compromise related to CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware15 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC5
This is a critical UAF vulnerability exploit that affected the android binder IPC system used in the wild and discovered by P0
CVE-2019-2215HIGHunder attack15 Apr 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC
Joomla! < 4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMunder attack15 Apr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
OS 12.0 & 12.1.2 - Jailbreak with CVE-2019-6225
CVE-2019-622515 Apr 2024
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISK
open
GitHub PoC3
dcheng69/CVE-2022-0185-Case-Study
CVE-2022-0185HIGHunder attack15 Apr 2024
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
GitHub PoC
Vulnerabilidad de palo alto
CVE-2024-3400CRITICALunder attackransomware14 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC13
momika233/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware14 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC3
A reproduction of CVE-2019-18634, sudo privilege escalation with buffer overflow.
CVE-2019-1863414 Apr 2024
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
GitHub PoC2
cve-2020-1938 Tomcat-Ajp-lfi.git脚本
CVE-2020-1938CRITICALunder attack14 Apr 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC2
Simple CVE-2024-24576 PoC in Julia
CVE-2024-24576CRITICAL14 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC1
Python script for CMS Made Simple 2.1.6 - Remote Code Execution.
CVE-2018-744814 Apr 2024
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RISK
open
GitHub PoC
CVE-2024-21413 Setup for CW
CVE-2024-21413CRITICALunder attack13 Apr 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC335
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
CVE-2024-21338HIGHunder attackransomware13 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail
CVE-2020-13965MEDIUMunder attack13 Apr 2024
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta
85RISK
open
GitHub PoC2
PoC MinIO vulnerability exploit
CVE-2023-28432HIGHunder attack13 Apr 2024
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
MAL-004: Command Injection Bypass for CVE-2020-12641 in Roundcube Webmail
CVE-2020-12641CRITICALunder attack13 Apr 2024
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RISK
open
GitHub PoC
La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y 5.6.1 de la herramienta de compresión XZ.
CVE-2024-3094CRITICAL13 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Demonstration of CVE-2020-11023
CVE-2020-11023MEDIUMunder attack13 Apr 2024
Potential XSS vulnerability in jQuery
85RISK
open
GitHub PoC
FoxyProxys/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
previouspage 232 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.