Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
76,542 exploits
GitHub PoC4
D1se0/CVE-2024-10924-Bypass-MFA-Wordpress-LAB
CVE-2024-10924CRITICAL01 Dec 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL01 Dec 2024
Code Injection in pyload/pyload
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-37042CRITICALunder attackransomware01 Dec 2024
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL01 Dec 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC37
cve-2024-42327 ZBX-25623
CVE-2024-42327CRITICAL01 Dec 2024
SQL injection in user.get API
70RISK
open
GitHub PoC3
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC
CVE-2024-0012CRITICALunder attackransomware30 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC18
PoC CVE-2023-28205: Apple WebKit Use-After-Free Vulnerability
CVE-2023-28205HIGHunder attack30 Nov 2024
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 a
76RISK
open
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALunder attack30 Nov 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
VulnCheck XDB
client-side
CVE-2023-28205HIGHunder attack30 Nov 2024
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 a
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware30 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware30 Nov 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-52301HIGH30 Nov 2024
Laravel allows environment manipulation via query string
53RISK
open
GitHub PoC
dagowda/Zabbix-cve-2022-23131-SSO-bypass
CVE-2022-23131CRITICALunder attack30 Nov 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC
CVE-2023-41425 (XSS to RCE, Wonder CMS 3.2.0 <= 3.4.2)
CVE-2023-41425MEDIUM30 Nov 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC
0xshoriful/CVE-2024-52380
CVE-2024-52380CRITICAL30 Nov 2024
WordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
0xshoriful/CVE-2024-10470
CVE-2024-10470CRITICAL30 Nov 2024
WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
60RISK
open
GitHub PoC
Raeezrbr/CVE-2024-5084
CVE-2024-5084CRITICAL30 Nov 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware29 Nov 2024
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-21683HIGH29 Nov 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISK
open
VulnCheck XDB
infoleak
CVE-2018-13379CRITICALunder attackransomware29 Nov 2024
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC
alyaapm/CVE-2025-55182-shellinteractive
CVE-2025-55182CRITICALunder attackransomware29 Nov 2024
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
Quantum-Sicarius/CVE-2024-49369
CVE-2024-49369CRITICAL29 Nov 2024
Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
48RISK
open
GitHub PoC
CVE-2024-36401-GeoServer Property 表达式注入 Rce woodpecker-framework 插件
CVE-2024-36401CRITICALunder attack28 Nov 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23113CRITICALunder attack28 Nov 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open
GitHub PoC5
POC - CVE-2024-21534 Jsonpath-plus vulnerable to Remote Code Execution (RCE) due to improper input sanitization
CVE-2024-21534CRITICAL28 Nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RISK
open
GitHub PoC2
CVE-2024-55215
CVE-2024-55215CRITICAL28 Nov 2024
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter
48RISK
open
VulnCheck XDB
infoleak
CVE-2023-43208CRITICALunder attackransomware28 Nov 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
In this project, we found a recent attack through the malicious container and implemented a security mechanism to stop it.
CVE-2019-573628 Nov 2024
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC2
Use java.net.InetAddress for detection
CVE-2023-43208CRITICALunder attackransomware28 Nov 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL27 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
previouspage 329 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.