Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,402cataloged exploits
34,906CVEs with public exploitation
24,695lab-tested
76,313 exploits
GitHub PoC5
A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282, CVE-2023-46805, and CVE-2024-21887.
CVE-2024-21887CRITICALunder attackransomware19 Jan 2025
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISK
open
GitHub PoC3
This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs
CVE-2024-41570CRITICAL19 Jan 2025
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RISK
open
GitHub PoC16
Havoc SSRF to RCE
CVE-2024-41570CRITICAL19 Jan 2025
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RISK
open
GitHub PoC5
A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282, CVE-2023-46805, and CVE-2024-21887.
CVE-2025-0282CRITICALunder attackransomware19 Jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
GitHub PoC1
RapidResetClient
CVE-2023-44487HIGHunder attack18 Jan 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack18 Jan 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC1
masa42/CVE-2024-38821-POC
CVE-2024-38821CRITICAL18 Jan 2025
Authorization Bypass of Static Resources in WebFlux Applications
48RISK
open
GitHub PoC3
Picsmize plugin for WordPress is vulnerable to arbitrary file uploads.
CVE-2024-52380CRITICAL18 Jan 2025
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
PoC: Plugin: Zita Site Builder <= 1.0.2 - Arbitrary Plugin Installation
CVE-2024-54369CRITICAL18 Jan 2025
WordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
48RISK
open
GitHub PoC
Exploit CVE-2024-54262: Arbitrary File Upload in Import Export for WooCommerce
CVE-2024-54262CRITICAL17 Jan 2025
WordPress Import Export For WooCommerce plugin <= 1.6.2 - Arbitrary File Upload vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack17 Jan 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware17 Jan 2025
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-24816CRITICALunder attack17 Jan 2025
Improper Control of Generation of Code in jai-ext
100RISK
open
GitHub PoC1
c1ph3rbyt3/CVE-2022-24816
CVE-2022-24816CRITICALunder attack17 Jan 2025
Improper Control of Generation of Code in jai-ext
100RISK
open
GitHub PoC15
CVE-2024-57727
CVE-2024-57727CRITICALunder attackransomware17 Jan 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RISK
open
GitHub PoC
This is a repository that aims to provide research material on CVE-2020-14882 as part of a project in partial fullfilment of ACS EDU Program.
CVE-2020-14882CRITICALunder attack17 Jan 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC3
CVE-2024-43468 SCCM SQL Injection Exploit (mTLS unextractable client cert from MacOS keychain version)
CVE-2024-43468CRITICALunder attack17 Jan 2025
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RISK
open
VulnCheck XDB
initial-access
CVE-2024-43468CRITICALunder attack17 Jan 2025
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RISK
open
GitHub PoC
c1ph3rbyt3/CVE-2022-29464
CVE-2022-29464CRITICALunder attackransomware17 Jan 2025
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-57727CRITICALunder attackransomware17 Jan 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RISK
open
GitHub PoC1
Proof of concept for CVE-2022-31814
CVE-2022-31814CRITICAL16 Jan 2025
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL16 Jan 2025
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
GitHub PoC1
Incorrect Privilege Assignment vulnerability in nssTheme Wp NssUser Register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through 1.0.0.
CVE-2024-54363CRITICAL16 Jan 2025
WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-50967MEDIUM16 Jan 2025
The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-0282CRITICALunder attackransomware16 Jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware16 Jan 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
GitHub PoC87
Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group
CVE-2022-40684CRITICALunder attackransomware16 Jan 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC66
watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591
CVE-2024-55591CRITICALunder attackransomware16 Jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
GitHub PoC1
Palo Alto RCE Vuln
CVE-2024-9474MEDIUMunder attackransomware16 Jan 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
GitHub PoC1
Proof of concept for CVE-2022-31814
CVE-2022-31814CRITICAL16 Jan 2025
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open
previouspage 314 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.