Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack13 Feb 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALunder attack13 Feb 2025
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open
GitHub PoC
CMS Made Simple < 2.2.10 - SQL Injection python3
CVE-2019-905313 Feb 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
luke0x90/CVE-2021-21551
CVE-2021-21551HIGHunder attack13 Feb 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
VulnCheck XDB
client-side
CVE-2024-42009CRITICALunder attack13 Feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-24865CRITICAL13 Feb 2025
mySCADA myPRO Manager Missing Authentication for Critical Function
43RISK
open
GitHub PoC2
POC for Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010
CVE-2024-42008CRITICAL13 Feb 2025
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7
60RISK
open
Metasploit300
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
CVE-2025-22896CRITICAL13 Feb 2025
mySCADA myPRO Manager Cleartext Storage of Sensitive Information
43RISK
open
VulnCheck XDB
initial-access
CVE-2025-0108HIGHunder attack13 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALunder attack13 Feb 2025
Remote code execution in Wazuh server
100RISK
open
GitHub PoC32
Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)
CVE-2025-0108HIGHunder attack13 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack12 Feb 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
Metasploit300
Audiobookshelf Unauthenticated API Authentication Bypass Scanner
CVE-2025-25205HIGH12 Feb 2025
Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
36RISK
open
GitHub PoC
An unauthenticated attacker can force server points to a shell file like ‘/bin/sh’ and execute arbitrary commands due to the failure in verifying the URL which leads to path traversal to any file that exists in the system. Nostromo’s versions such as 1.9.6 fail to verify this URL
CVE-2019-16278CRITICALunder attack12 Feb 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC
qnole000/CVE-2024-51378
CVE-2024-51378CRITICALunder attackransomware12 Feb 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH12 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
GitHub PoC
Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.
CVE-2021-43798HIGHunder attack12 Feb 2025
Grafana path traversal
100RISK
open
GitHub PoC
Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware12 Feb 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware12 Feb 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack12 Feb 2025
Grafana path traversal
100RISK
open
VulnCheck XDB
client-side
CVE-2024-42009CRITICALunder attack11 Feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
GitHub PoC
Alienfader/CVE-2020-29607
CVE-2020-2960711 Feb 2025
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL11 Feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC1
Exploit for Apache OFBiz - CVE-2024-38856
CVE-2024-38856HIGHunder attack11 Feb 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53704HIGHunder attackransomware11 Feb 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISK
open
GitHub PoC2
demonstriert, wie mittels missbräuchlicher Nutzung eines Swap-Cookies eine VPN-Session übernommen werden kann. Wichtig: Dieses Projekt dient ausschliesslich zu Bildungs- und Forschungszwecken – bitte nur in Umgebungen verwenden, in denen Du explizit authorisiert bist.
CVE-2024-53704HIGHunder attackransomware11 Feb 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack11 Feb 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC4
This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail system, which, when triggered, exfiltrates email content from the victim’s inbox.
CVE-2024-42009CRITICALunder attack11 Feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
GitHub PoC1
yenyangmjaze/cve-2024-10914
CVE-2024-10914CRITICAL11 Feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
CVE-2024-27348CRITICALunder attack10 Feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
previouspage 308 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.