Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack10 Feb 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
Yami0x777/Belsen_Group-et-exploitation-de-la-CVE-2022-40684
CVE-2022-40684CRITICALunder attackransomware10 Feb 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-3864610 Feb 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
GitHub PoC
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
CVE-2024-27348CRITICALunder attack10 Feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
GitHub PoC1
cve-2019-5420 POC simple ruby script
CVE-2019-542010 Feb 2025
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-27348CRITICALunder attack10 Feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-0847HIGHunder attack09 Feb 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
0x7556/CVE-2024-55591
CVE-2024-55591CRITICALunder attackransomware09 Feb 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
GitHub PoC
skrkcb2/CVE-2024-5452
CVE-2024-5452CRITICAL09 Feb 2025
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
53RISK
open
GitHub PoC
RogelioPumajulca/CVE-2022-0847
CVE-2022-0847HIGHunder attack09 Feb 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC1
SSHEnum es una herramienta de enumeración de usuarios SSH basada en CVE-2018-15473. Permite detectar usuarios válidos aprovechando respuestas diferenciadas del servidor. Es rápida, compatible con Python 3.12 y soporta wordlists. Uso exclusivo para auditoría y pruebas de seguridad autorizadas.
CVE-2018-15473MEDIUM09 Feb 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC
This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege escalation on Ubuntu 20.04 with sudo version 1.8.31 and glibc version 2.31. It includes an assembly-based exploit, a shared object payload, and a Makefile for automated compilation.
CVE-2021-3156HIGHunder attack08 Feb 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
pz-frontend-manager < 1.0.6 - CSRF Profile Picture Exploit
CVE-2024-6244HIGH08 Feb 2025
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack08 Feb 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-39713HIGH07 Feb 2025
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RISK
open
GitHub PoC3
Snizi/Moodle-CVE-2024-43425-Exploit
CVE-2024-43425HIGH07 Feb 2025
Moodle: remote code execution via calculated question types
78RISK
open
GitHub PoC4
Cityworks deserialization of untrusted data vulnerability Detection
CVE-2025-0994HIGHunder attack07 Feb 2025
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to
83RISK
open
Metasploit600
InvokeAI RCE
CVE-2024-12029CRITICAL07 Feb 2025
Remote Code Execution via Model Deserialization in invoke-ai/invokeai
63RISK
open
GitHub PoC
PoC of CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware07 Feb 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2022-30190HIGHunder attackransomware07 Feb 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Directory Traversal Exploit written in Bash for NVMS-1000 (CVE-2019-20085).
CVE-2019-20085HIGHunder attack06 Feb 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware06 Feb 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
GitHub PoC1
This is a Python script that exploits the CVE-2024-6624 vulnerability in the JSON API User <= 3.9.3 plugin for WordPress.
CVE-2024-6624CRITICAL06 Feb 2025
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISK
open
GitHub PoC4
Python script for CVE-2024-0012 / CVE-2024-9474 exploit
CVE-2024-0012CRITICALunder attackransomware06 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware06 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-20085HIGHunder attack06 Feb 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware05 Feb 2025
Information disclosure
100RISK
open
Metasploit600
D-Tale RCE
CVE-2025-065505 Feb 2025
15RISK
open
Metasploit600
D-Tale RCE
CVE-2024-3408CRITICAL05 Feb 2025
Authentication Bypass and RCE in man-group/dtale
85RISK
open
GitHub PoC
daikinitanda/-CVE-2024-47875-
CVE-2024-47875CRITICAL05 Feb 2025
DOMPurify nesting-based mXSS
48RISK
open
previouspage 309 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.