Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
76,496 exploits
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware11 Dec 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC
Cái này dựng lên với mục đích cho ae tham khảo, chê thì đừng có xem. :))))
CVE-2023-346011 Dec 2024
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware11 Dec 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-50623CRITICALunder attackransomware11 Dec 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISK
open
GitHub PoC1
Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp directory; script has been adjusted accordingly.
CVE-2022-37706HIGH10 Dec 2024
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open
GitHub PoC1
CVE-2024-55557
CVE-2024-55557CRITICAL10 Dec 2024
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti
48RISK
open
GitHub PoC1
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
CVE-2024-12209CRITICAL09 Dec 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-12209CRITICAL09 Dec 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISK
open
GitHub PoC
Jimmy01240397/CVE-2012-1823-Analyze
CVE-2012-1823CRITICALunder attack09 Dec 2024
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM09 Dec 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC
A simple python script to test for CVE-2024-9441.
CVE-2024-9441CRITICAL09 Dec 2024
Linear eMerge e3-Series Forgot Password Command Injection
60RISK
open
GitHub PoC1
This repository is a proof of concept (POC) for CVE-2024-23334, demonstrating an attempt to replicate the bug in aiohttp that leads to Local File Inclusion (LFI).
CVE-2024-23334MEDIUM09 Dec 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
Metasploit600
Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution
CVE-2024-55956CRITICALunder attackransomware09 Dec 2024
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can impo
95RISK
open
GitHub PoC
This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)
CVE-2024-23346CRITICAL09 Dec 2024
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open
GitHub PoC
Danyw24/CVE-2004-1561-Icecast-Header-Overwrite-buffer-overflow-RCE-2.0.1-Win32-
CVE-2004-156109 Dec 2024
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-21389HIGH09 Dec 2024
BuddyPress privilege escalation via REST API
61RISK
open
GitHub PoC4
D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins
CVE-2024-23897CRITICALunder attackransomware08 Dec 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server
CVE-2017-5638CRITICALunder attackransomware08 Dec 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
CVE-2021-2301708 Dec 2024
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware08 Dec 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
Technical Details and Exploit for CVE-2024-11392
CVE-2024-11392HIGH07 Dec 2024
Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
41RISK
open
GitHub PoC3
POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method
CVE-2024-42327CRITICAL07 Dec 2024
SQL injection in user.get API
70RISK
open
GitHub PoC
Calibre Remote Code Execution
CVE-2024-6782CRITICAL07 Dec 2024
Calibre Remote Code Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL07 Dec 2024
Calibre Remote Code Execution
85RISK
open
GitHub PoC
lu4m575/CVE-2024-35286_scan.nse
CVE-2024-35286CRITICAL06 Dec 2024
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RISK
open
GitHub PoC4
CVE-2024-10914 D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL06 Dec 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL06 Dec 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-9465CRITICALunder attack06 Dec 2024
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISK
open
GitHub PoC
fredagsguf/Windows-CVE-2024-38063
CVE-2024-38063CRITICAL06 Dec 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC3
depers-rus/CVE-2024-42327
CVE-2024-42327CRITICAL06 Dec 2024
SQL injection in user.get API
70RISK
open
previouspage 326 / 2,550next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.