Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
GitHub PoC
progress moveit cve-2024-5806
CVE-2024-5806CRITICAL08 Mar 2025
MOVEit Transfer Authentication Bypass Vulnerability
85RISK
open
GitHub PoC
Zimbra CVE-2024-45519
CVE-2024-45519CRITICALunder attack08 Mar 2025
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
GitHub PoC
elphon/CVE-2007-2447-Exploit
CVE-2007-244708 Mar 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
initial-access
CVE-2024-5806CRITICAL08 Mar 2025
MOVEit Transfer Authentication Bypass Vulnerability
85RISK
open
GitHub PoC
CVE-2023-40028 is a security vulnerability affecting Ghost CMS versions prior to 5.59.1.
CVE-2023-40028MEDIUM07 Mar 2025
Arbitrary file read via symlinks in Ghost
45RISK
open
GitHub PoC4
Python3 Rewrite of SmarterMail < Build 6985 Remote Code Execution found by 1F98D (CVE-2019-7214) POC
CVE-2019-721407 Mar 2025
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISK
open
GitHub PoC1
A Critical Windows OLE Zero-Click Vulnerability. This is a proof-of-concept for CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability (CVSS 9.8). This is a memory corruption PoC
CVE-2025-21298CRITICAL07 Mar 2025
Windows OLE Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use of the Trend Micro Deep Security solution to prevent such attacks.
CVE-2020-1472MEDIUMunder attackransomware07 Mar 2025
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2023-4911HIGHunder attack06 Mar 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack06 Mar 2025
Grafana path traversal
100RISK
open
GitHub PoC
HFS 2.3m SERVER RCE Vulnerability exploit
CVE-2024-23692CRITICALunder attack06 Mar 2025
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
GitHub PoC2
Arbitrary file read in Grafana allows an attacker to read server files by abusing a path traversal.
CVE-2021-43798HIGHunder attack06 Mar 2025
Grafana path traversal
100RISK
open
GitHub PoC
This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.
CVE-2024-32002CRITICAL06 Mar 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting repositories with submodules in a specific way, an attacker can exploit symlink handling on case-insensitive filesystems to write files into the .git/ directory, leading to the execution of malicious hooks.
CVE-2024-32002CRITICAL06 Mar 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attack06 Mar 2025
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack05 Mar 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2023-5016405 Mar 2025
Apache Struts: File upload component had a directory traversal vulnerability
45RISK
open
GitHub PoC
Sornphut/OverlayFS---CVE-2021-3493
CVE-2021-3493HIGHunder attack05 Mar 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
GazettEl/CVE-2020-24186
CVE-2020-24186CRITICAL05 Mar 2025
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open
GitHub PoC
This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL injection to extract the username, email, and password hash from the database. Additionally, it supports password cracking using a wordlist.
CVE-2019-905305 Mar 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
PoC exploit for CVE-2012-2982 (Webmin RCE), for educational purposes.
CVE-2012-298205 Mar 2025
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
VulnCheck XDB
initial-access
CVE-2019-023205 Mar 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC2
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2025-1307CRITICAL05 Mar 2025
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
48RISK
open
GitHub PoC
x3m1Sec/CVE-2019-0232_tomcat_cgi_exploit
CVE-2019-023205 Mar 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHunder attack04 Mar 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
build-script for CVE-2024-46507 and CVE-2024-46508
CVE-2024-46507HIGH04 Mar 2025
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor
56RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-36842HIGH04 Mar 2025
Migration, Backup, Staging – WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-46507HIGH04 Mar 2025
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor
56RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-8963CRITICALunder attack04 Mar 2025
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-8190HIGHunder attack04 Mar 2025
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RISK
open
previouspage 303 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.