Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
13,708 exploits
GitHub PoC
churamanib/CVE-2023-0386
CVE-2023-0386HIGHunder attack05 Apr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC3
A tutorial on how to detect the CVE 2024-3094
CVE-2024-3094CRITICAL04 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Scans liblzma from xu-utils for backdoor (CVE-2024-3094)
CVE-2024-3094CRITICAL04 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC1
A small repo with a single playbook.
CVE-2024-3094CRITICAL04 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC4
Ansible playbooks designed to check and remediate CVE-2024-3094 (XZ Backdoor)
CVE-2024-3094CRITICAL04 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC1
The CVE-2024-3094 Checker is a Bash tool for identifying if Linux systems are at risk from the CVE-2024-3094 flaw in XZ/LZMA utilities. It checks XZ versions, SSHD's LZMA linkage, and scans for specific byte patterns, delivering results in a concise table format.
CVE-2024-3094CRITICAL03 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
This is a container environment running CVE-2024-3094 sshd backdoor instance, working with https://github.com/amlweems/xzbot project. IT IS NOT Docker, just implemented by chroot.
CVE-2024-3094CRITICAL03 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
The repository consists of a checker file that confirms if your xz version and xz-utils package is vulnerable to CVE-2024-3094.
CVE-2024-3094CRITICAL03 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC2
Verify if your installed version of xz-utils is vulnerable to CVE-2024-3094 backdoor
CVE-2024-3094CRITICAL03 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC2
Collection of Detection, Fix, and exploit for CVE-2024-3094
CVE-2024-3094CRITICAL03 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
LAB: TẤN CÔNG HỆ ĐIỀU HÀNH WINDOWS DỰA VÀO LỖ HỔNG GIAO THỨC SMB.
CVE-2017-0144HIGHunder attackransomware03 Apr 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC3
Alicey0719/docker-POC_CVE-2024-1086
CVE-2024-1086HIGHunder attackransomware03 Apr 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC1
cjybao/CVE-2024-1709-and-CVE-2024-1708
CVE-2024-1709CRITICALunder attackransomware02 Apr 2024
Authentication bypass using an alternate path or channel
100RISK
open
GitHub PoC
Em fevereiro de 2024, foi identificado duas novas vulnerabilidades que afetam o servidor JetBrains TeamCity (CVE-2024-27198 e CVE-2024-27199)
CVE-2024-27198CRITICALunder attackransomware02 Apr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC3
apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC1
This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo Application written with Node.js which is containing Remote Code Execution Vulnerability (CVE-2023-32314) for demonstrating all addvantages of this architecture to manage Honeypot systems
CVE-2023-32314CRITICAL02 Apr 2024
Sandbox Escape
48RISK
open
GitHub PoC
YangHyperData/LOGJ4_PocShell_CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware02 Apr 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2024-3094 XZ Backdoor Detector
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC2
Detectar CVE-2024-3094
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC3
CVE-2024-3094 - Checker (fix for arch etc)
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC14
Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC17
XZ Backdoor Extract(Test on Ubuntu 23.10)
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC4
Education purpose for CVE-2018-10933
CVE-2018-10933CRITICAL01 Apr 2024
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
dah4k/CVE-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
ackemed/detectar_cve-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC3
Checker - CVE-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Obsidian notes about CVE-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC3,555
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC3
Herramientas de linux para diferentes funciones.
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
previouspage 234 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.