Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
76,496 exploits
VulnCheck XDB
initial-access
CVE-2024-50623CRITICALunder attackransomware31 Dec 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISK
open
GitHub PoC5
Cleo 远程代码执行漏洞批量检测脚本(CVE-2024-50623)
CVE-2024-50623CRITICALunder attackransomware31 Dec 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISK
open
GitHub PoC1
CVE-2024-54819
CVE-2024-54819CRITICAL30 Dec 2024
I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input valid
53RISK
open
GitHub PoC
luongchivi/Preproduce-CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware30 Dec 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware30 Dec 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC3
CVE-2023-38831 (PoC) - WinRAR Exploit
CVE-2023-38831HIGHunder attackransomware30 Dec 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC4
AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF challenges. Strictly for authorized and educational use only!
CVE-2017-0144HIGHunder attackransomware30 Dec 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH30 Dec 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
GitHub PoC12
math-x-io/CVE-2024-54152-poc
CVE-2024-54152CRITICAL30 Dec 2024
Angular Expressions - Remote Code Execution when using locals
48RISK
open
VulnCheck XDB
local
CVE-2023-38831HIGHunder attackransomware30 Dec 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-023229 Dec 2024
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-21182HIGHunder attack29 Dec 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RISK
open
VulnCheck XDB
initial-access
CVE-2024-21182HIGHunder attack29 Dec 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RISK
open
GitHub PoC2
Hi this is a revised and enhanced code for CVE-2019-0232
CVE-2019-023229 Dec 2024
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC2
PoC for CVE-2024-21182
CVE-2024-21182HIGHunder attack29 Dec 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RISK
open
GitHub PoC1
PoC for CVE-2024-21182
CVE-2024-21182HIGHunder attack29 Dec 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RISK
open
GitHub PoC2
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. (CRITICAL)
CVE-2024-7954CRITICAL28 Dec 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC
Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE
CVE-2024-8069MEDIUMunder attack28 Dec 2024
Limited remote code execution with privilege of a NetworkService Account access
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL28 Dec 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC1
Nxploited/CVE-2024-9234
CVE-2024-9234CRITICAL28 Dec 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC
A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized domain controller access.
CVE-2020-1472MEDIUMunder attackransomware28 Dec 2024
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC3
CVE-2023-40028 PoC Exploit
CVE-2023-40028MEDIUM28 Dec 2024
Arbitrary file read via symlinks in Ghost
45RISK
open
VulnCheck XDB
initial-access
CVE-2024-9234CRITICAL28 Dec 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC1
CVE-2024-50379-exp
CVE-2024-50379CRITICAL28 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48456HIGH27 Dec 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
41RISK
open
GitHub PoC
Nxploited/CVE-2024-9933
CVE-2024-9933CRITICAL27 Dec 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISK
open
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48457HIGH27 Dec 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
36RISK
open
Metasploit600
Netis Router Exploit Chain Reactor (CVE-2024-48455, CVE-2024-48456 and CVE-2024-48457).
CVE-2024-48455LOW27 Dec 2024
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi
23RISK
open
GitHub PoC
Testing the latset Apache Tomcat CVE-2024-50379 Vuln
CVE-2024-50379CRITICAL26 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-2291126 Dec 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
previouspage 321 / 2,550next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.