Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
76,496 exploits
VulnCheck XDB
infoleak
CVE-2024-12025HIGH19 Dec 2024
Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
56RISK
open
GitHub PoC
Import Export For WooCommerce <= 1.5 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2024-54262CRITICAL19 Dec 2024
WordPress Import Export For WooCommerce plugin <= 1.6.2 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC1
webmin or minisever RCE
CVE-2019-15107CRITICALunder attackransomware19 Dec 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC4
v3153/CVE-2024-50379-POC
CVE-2024-50379CRITICAL18 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
GitHub PoC1
Adobe ColdFusion 8 - Remote Command Execution (RCE)
CVE-2009-226518 Dec 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
GitHub PoC2
dustblessnotdust/CVE-2024-53677-S2-067-thread
CVE-2024-53677CRITICAL18 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC
CVE-2023-4966-exploit
CVE-2023-4966CRITICALunder attackransomware18 Dec 2024
Unauthenticated sensitive information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
initial-access
CVE-2009-226518 Dec 2024
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL18 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL17 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC6
Proof of concept (POC) for CVE-2024-45337
CVE-2024-45337CRITICAL17 Dec 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISK
open
GitHub PoC1
An example project that showcases golang code vulnerable to CVE-2024-45337
CVE-2024-45337CRITICAL17 Dec 2024
Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
48RISK
open
GitHub PoC3
yangyanglo/CVE-2024-53677
CVE-2024-53677CRITICAL17 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC3
A Docker-based environment to reproduce the CVE-2024-53677 vulnerability in Apache Struts 2.
CVE-2024-53677CRITICAL17 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC14
A short scraper looking for a POC of CVE-2024-49112
CVE-2024-49112CRITICAL16 Dec 2024
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RISK
open
GitHub PoC21
LLfam/CVE-2024-1086
CVE-2024-1086HIGHunder attackransomware16 Dec 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC
Rahul-Thakur7/CVE-2023-21554
CVE-2023-21554CRITICAL16 Dec 2024
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open
GitHub PoC
t0mmy4/CVE-2019-12725-modified-exp
CVE-2019-1272516 Dec 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
GitHub PoC1
The EXP/POC of CVE-2019-12725
CVE-2019-1272516 Dec 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
GitHub PoC
DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection
CVE-2024-50507CRITICAL16 Dec 2024
WordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
48RISK
open
VulnCheck XDB
local
CVE-2024-1086HIGHunder attackransomware16 Dec 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
local
CVE-2024-49039HIGHunder attackransomware16 Dec 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2019-1272516 Dec 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-1272516 Dec 2024
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware16 Dec 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2024-12356CRITICALunder attack16 Dec 2024
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
95RISK
open
GitHub PoC
redspy-sec/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware16 Dec 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2025-1094HIGH16 Dec 2024
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISK
open
VulnCheck XDB
local
CVE-2024-0582HIGH15 Dec 2024
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open
previouspage 324 / 2,550next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.