Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
76,496 exploits
GitHub PoC1
CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins, risking RCE, SQLi, XSS, and backdoors.
CVE-2024-11972CRITICAL13 Jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open
GitHub PoC3
CVE-2024-35250 PoC - Optimized & Condensed Form of Varwara's PoC
CVE-2024-35250HIGHunder attack13 Jan 2025
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
GitHub PoC1
VRPConnector <= 2.0.1 - Unauthenticated PHP Object Injection
CVE-2024-56058CRITICAL13 Jan 2025
WordPress VRPConnector plugin <= 2.0.1 - PHP Object Injection vulnerability
48RISK
open
GitHub PoC1
Partners <= 0.2.0 - Unauthenticated PHP Object Injection
CVE-2024-56059CRITICAL13 Jan 2025
WordPress Partners plugin <= 0.2.0 - PHP Object Injection vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-11972CRITICAL13 Jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open
VulnCheck XDB
infoleak
CVE-2024-10571CRITICAL13 Jan 2025
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
63RISK
open
VulnCheck XDB
local
CVE-2024-35250HIGHunder attack13 Jan 2025
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
VulnCheck XDB
initial-access
CVE-2024-9707CRITICAL12 Jan 2025
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RISK
open
VulnCheck XDB
infoleak
CVE-2024-3605CRITICAL12 Jan 2025
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-10586CRITICAL12 Jan 2025
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RISK
open
GitHub PoC1
RSVP ME <= 1.9.9 - Unauthenticated SQL Injection
CVE-2024-50491CRITICAL12 Jan 2025
WordPress RSVP ME plugin <= 1.9.9 - SQL Injection vulnerability
48RISK
open
GitHub PoC2
kcfg bypass example - CVE-2024-21338
CVE-2024-21338HIGHunder attackransomware12 Jan 2025
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC4
# CVE-2025-0282: Remote Code Execution Vulnerability in [StorkS]
CVE-2025-0282CRITICALunder attackransomware12 Jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
GitHub PoC1
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
CVE-2024-3605CRITICAL12 Jan 2025
WP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
63RISK
open
GitHub PoC17
CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection
CVE-2024-50603CRITICALunder attack12 Jan 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RISK
open
GitHub PoC
he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)
CVE-2024-9707CRITICAL12 Jan 2025
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RISK
open
Metasploit300
SimpleHelp Path Traversal Vulnerability CVE-2024-57727
CVE-2024-57727CRITICALunder attackransomware12 Jan 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl
100RISK
open
GitHub PoC1
Subscribe to Category <= 2.7.4 - Unauthenticated SQL Injection
CVE-2023-32590CRITICAL12 Jan 2025
WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to SQL Injection
63RISK
open
VulnCheck XDB
infoleak
CVE-2024-50603CRITICALunder attack12 Jan 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware12 Jan 2025
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
Nxploited/CVE-2024-10586-Poc
CVE-2024-10586CRITICAL12 Jan 2025
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RISK
open
GitHub PoC
Nxploited/CVE-2024-49328-exploit
CVE-2024-49328CRITICAL11 Jan 2025
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RISK
open
GitHub PoC1
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
CVE-2024-12877CRITICAL11 Jan 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RISK
open
GitHub PoC
Nxploited/CVE-2024-9932-POC
CVE-2024-9932CRITICAL11 Jan 2025
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
poc-cve-2023-3824
CVE-2023-3824CRITICAL11 Jan 2025
Buffer overflow and overread in phar_dir_read()
53RISK
open
GitHub PoC
A Python script to detect CVE-2024-41713, a directory traversal vulnerability in Apache HTTP Server, enabling unauthorized access to restricted resources. This tool is for educational purposes and authorized testing only. Unauthorized usage is unethical and illegal.
CVE-2024-41713CRITICALunder attackransomware11 Jan 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISK
open
GitHub PoC53
CVE-2025-0282 is a critical vulnerability found in Ivanti Connect Secure, allowing Remote Command Execution (RCE) through a buffer overflow exploit.
CVE-2025-0282CRITICALunder attackransomware11 Jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack11 Jan 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
VulnCheck XDB
infoleak
CVE-2024-12877CRITICAL11 Jan 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RISK
open
GitHub PoC
Exploit implementation for CVE-2021-21551
CVE-2021-21551HIGHunder attack11 Jan 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
previouspage 318 / 2,550next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.