Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL17 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack17 Feb 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
GitHub PoC
sariamubeen/CVE-2024-10924
CVE-2024-10924CRITICAL17 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC1
skrkcb2/CVE-2025-0851
CVE-2025-0851CRITICAL17 Feb 2025
Path traversal issue in Deep Java Library
53RISK
open
GitHub PoC
This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to detect exploitation attempts in log data.
CVE-2021-44228CRITICALunder attackransomware17 Feb 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.
CVE-2024-4367MEDIUM17 Feb 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC3
sariamubeen/CVE-2023-7028
CVE-2023-7028CRITICALunder attack17 Feb 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
GitHub PoC
ModeBrutal/CVE-2024-5084-Auto-Exploit
CVE-2024-5084CRITICAL16 Feb 2025
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
GitHub PoC
This repository contains a Python script to exploit two vulnerabilities: CVE-2019-18818 and CVE-2019-19609.
CVE-2019-1881816 Feb 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
GitHub PoC9
POC for CVE-2024-42327: Zabbix Privilege Escalation -> RCE
CVE-2024-42327CRITICAL16 Feb 2025
SQL injection in user.get API
70RISK
open
GitHub PoC43
CVE-2025-24016: Wazuh Unsafe Deserialization Remote Code Execution (RCE)
CVE-2025-24016CRITICALunder attack16 Feb 2025
Remote code execution in Wazuh server
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1881816 Feb 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
GitHub PoC
Explore CVE-2023-33580 (XSS) & CVE-2023-33584 (SQLI) discovered by me. Dive into vulnerabilities and exploits for insights.
CVE-2023-3358016 Feb 2025
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-24016CRITICALunder attack16 Feb 2025
Remote code execution in Wazuh server
100RISK
open
GitHub PoC
hopsypopsy8/CVE-2020-1938-Exploitation
CVE-2020-1938CRITICALunder attack15 Feb 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC1
Browser exploitation framework for Chakra (Edge). Written as part of OSEE preparation. Demo bug: CVE-2019-0567
CVE-2019-056715 Feb 2025
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RISK
open
GitHub PoC2
A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor authentication (2FA). Includes mitigation techniques to secure affected WordPress sites.
CVE-2024-10924CRITICAL14 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
php-cgi-cve-2024-4577
CVE-2024-4577CRITICALunder attackransomware14 Feb 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Didarul342/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware14 Feb 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware14 Feb 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware14 Feb 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack14 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL14 Feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC8
PoC exploit for CVE-2025-0108 - PAN-OS Authentication Bypass
CVE-2025-0108HIGHunder attack14 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-0108HIGHunder attack13 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL13 Feb 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC32
Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)
CVE-2025-0108HIGHunder attack13 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALunder attack13 Feb 2025
Remote code execution in Wazuh server
100RISK
open
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-24865CRITICAL13 Feb 2025
mySCADA myPRO Manager Missing Authentication for Critical Function
43RISK
open
previouspage 307 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.