Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
76,107 exploits
VulnCheck XDB
initial-access
CVE-2023-2812112 Apr 2025
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISK
open
GitHub PoC1
PHP CGI CVE-2024-4577 PoC
CVE-2024-4577CRITICALunder attackransomware12 Apr 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack12 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 Apr 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack12 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-1177CRITICAL12 Apr 2025
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
VulnCheck XDB
client-side
CVE-2024-7971HIGHunder attack12 Apr 2025
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH12 Apr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
GitHub PoC
ngyinkit/cve-2019-18634
CVE-2019-1863411 Apr 2025
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware11 Apr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware11 Apr 2025
Argument Injection in PHP-CGI
100RISK
open
Exploit-DB
RosarioSIS 7.6 - SQL Injection
CVE-2021-44567webappsphp11 Apr 2025
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunct
28RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack11 Apr 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
Exploit-DB
Gnuboard5 5.3.2.8 - SQL Injection
CVE-2020-18662webappsphp11 Apr 2025
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
23RISK
open
Exploit-DB
WebFileSys 2.31.0 - Directory Path Traversal
CVE-2024-53586MEDIUMwebappsmultiple11 Apr 2025
An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra
33RISK
open
Exploit-DB
flatCore 1.5 - Cross Site Request Forgery (CSRF)
CVE-2019-13961webappsphp11 Apr 2025
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.
23RISK
open
Exploit-DB
MagnusSolution magnusbilling 7.3.0 - Command Injection
CVE-2023-30258CRITICALwebappsmultiple11 Apr 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
Exploit-DB
NEWS-BUZZ News Management System 1.0 - SQL Injection
CVE-2024-10758MEDIUMwebappsphp11 Apr 2025
code-projects/anirbandutta9 Content Management System/News-Buzz index.php sql injection
33RISK
open
GitHub PoC1
A Python proof-of-concept exploit for CVE-2019-15107 - an unauthenticated remote code execution vulnerability in Webmin versions 1.890 through 1.920.
CVE-2019-15107CRITICALunder attackransomware11 Apr 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Exploit-DB
Roundcube Webmail 1.6.6 - Stored Cross Site Scripting (XSS)
CVE-2024-37383MEDIUMunder attackwebappsphp11 Apr 2025
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISK
open
GitHub PoC
PoC for exploitation of vulnerability CVE-2019-10149
CVE-2019-10149CRITICALunder attack11 Apr 2025
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
Exploit-DB
GetSimpleCMS 3.3.16 - Remote Code Execution (RCE)
CVE-2021-28976webappsphp11 Apr 2025
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
23RISK
open
Exploit-DB
phpIPAM 1.6 - Reflected Cross Site Scripting (XSS)
CVE-2023-24657MEDIUMwebappsphp11 Apr 2025
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack11 Apr 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALunder attack11 Apr 2025
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware11 Apr 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC3
Exploit PoC for CVE-2023-20198
CVE-2023-20198CRITICALunder attack11 Apr 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-282511 Apr 2025
35RISK
open
GitHub PoC43
CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现
CVE-2024-36401CRITICALunder attack11 Apr 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
Exploit-DB
MiniCMS 1.1 - Cross Site Scripting (XSS)
CVE-2018-1000638webappsphp11 Apr 2025
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={pa
23RISK
open
previouspage 280 / 2,537next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.