Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
13,708 exploits
GitHub PoC71
CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
FoxyProxys/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
PoC MinIO vulnerability exploit
CVE-2023-28432HIGHunder attack13 Apr 2024
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y 5.6.1 de la herramienta de compresión XZ.
CVE-2024-3094CRITICAL13 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Demonstration of CVE-2020-11023
CVE-2020-11023MEDIUMunder attack13 Apr 2024
Potential XSS vulnerability in jQuery
85RISK
open
GitHub PoC335
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
CVE-2024-21338HIGHunder attackransomware13 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC5
OpenMetadata_RCE (CVE-2024-28255) Batch scan/exploit
CVE-2024-28255CRITICAL12 Apr 2024
Authentication Bypass in OpenMetadata
85RISK
open
GitHub PoC1
CVE-2024-24576 PoC for Nim Lang
CVE-2024-24576CRITICAL11 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC1
Public exploit for CVE-2024-31777
CVE-2024-31777CRITICAL11 Apr 2024
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RISK
open
GitHub PoC2
0xWhoami35/CVE-2023-23752
CVE-2023-23752MEDIUMunder attack11 Apr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC50
CVE-2023-6319 proof of concept
CVE-2023-6319CRITICAL11 Apr 2024
Command injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service
48RISK
open
GitHub PoC2
adhikara13/CVE-2024-2389
CVE-2024-2389CRITICAL11 Apr 2024
Flowmon Unauthenticated Command Injection Vulnerability
85RISK
open
GitHub PoC5
D-Link NAS Command Execution Exploit
CVE-2024-3273HIGHunder attack10 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC1
Ray OS Command Injection RCE(Unauthorized)
CVE-2023-6019CRITICAL10 Apr 2024
Ray Command Injection in cpu_profile Parameter
85RISK
open
GitHub PoC20
CVE-2024-24576 Proof of Concept
CVE-2024-24576CRITICAL10 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC9
brains93/CVE-2024-24576-PoC-Python
CVE-2024-24576CRITICAL10 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC8
Apache OfBiz vulns
CVE-2024-32113CRITICALunder attack10 Apr 2024
Apache OFBiz: Path traversal leading to RCE
100RISK
open
GitHub PoC1
The script is from https://github.com/JohnHammond/msdt-follina, just make it simple for me to use it and this script aim at generating the payload for more information refer the johnn hammond link
CVE-2022-30190HIGHunder attackransomware09 Apr 2024
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC5
A PoC exploit for CVE-2024-3273 - D-Link Remote Code Execution RCE
CVE-2024-3273HIGHunder attack09 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC59
Example of CVE-2024-24576 use case.
CVE-2024-24576CRITICAL09 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC23
CVE-2024-2879 - LayerSlider 7.9.11 - 7.10.0 - Unauthenticated SQL Injection
CVE-2024-2879CRITICAL08 Apr 2024
The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.1
68RISK
open
GitHub PoC
CVE-2020-12641: Command Injection via “_im_convert_path” Parameter in Roundcube Webmail
CVE-2020-12641CRITICALunder attack08 Apr 2024
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RISK
open
GitHub PoC101
D-Link NAS CVE-2024-3273 Exploit Tool
CVE-2024-3273HIGHunder attack07 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC
Quick and dirty honeypot for CVE-2024-3273
CVE-2024-3273HIGHunder attack07 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC3
CVE-2021-42013 Vulnerability Scanner This Python script checks for the Remote Code Execution (RCE) vulnerability (CVE-2021-42013) in Apache 2.4.50.
CVE-2021-42013CRITICALunder attackransomware07 Apr 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC13
Exploit for CVE-2024-3273, supports single and multiple hosts
CVE-2024-3273HIGHunder attack07 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC
RomainBayle08/CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware06 Apr 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)
CVE-2024-3094CRITICAL06 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC6
An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.
CVE-2024-3094CRITICAL05 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
churamanib/CVE-2023-0386
CVE-2023-0386HIGHunder attack05 Apr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
previouspage 233 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.