Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
76,542 exploits
GitHub PoC1
letsr00t/CVE-2023-2163
CVE-2023-2163CRITICAL27 Nov 2024
Incorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation
48RISK
open
GitHub PoC6
Bypass del MFA en WordPress con el plugin Really Simple Security instalado entre las versiones 9.0.0 – 9.1.1.1.
CVE-2024-10924CRITICAL27 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
dlink vulnerability thing in python and rust
CVE-2024-10914CRITICAL27 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC7
A PoC exploit for CVE-2024-10914 - D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL27 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL27 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
0xDTC/Magento-eCommerce-RCE-CVE-2015-1397
CVE-2015-139727 Nov 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL27 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack27 Nov 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC2
CVE-2024-36401 (GeoServer Remote Code Execution)
CVE-2024-36401CRITICALunder attack27 Nov 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
local
CVE-2015-132827 Nov 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC1
Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible
CVE-2014-6271CRITICALunder attack26 Nov 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2022-28171HIGH26 Nov 2024
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
53RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack26 Nov 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864626 Nov 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack26 Nov 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack26 Nov 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-45354MEDIUM26 Nov 2024
WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-1263526 Nov 2024
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-2291126 Nov 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2021-36260CRITICALunder attack26 Nov 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH26 Nov 2024
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-51567CRITICALunder attackransomware26 Nov 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-43468CRITICALunder attack26 Nov 2024
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RISK
open
VulnCheck XDB
initial-access
CVE-2014-6278HIGHunder attack26 Nov 2024
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISK
open
GitHub PoC3
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
CVE-2017-7921CRITICALunder attack26 Nov 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC3
WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation
CVE-2024-10542CRITICAL26 Nov 2024
Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation
53RISK
open
VulnCheck XDB
local
CVE-2024-38193HIGHunder attack26 Nov 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC1
Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability
CVE-2012-183126 Nov 2024
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RISK
open
GitHub PoC96
synacktiv/CVE-2024-43468
CVE-2024-43468CRITICALunder attack26 Nov 2024
Microsoft Configuration Manager Remote Code Execution Vulnerability
90RISK
open
GitHub PoC
Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you cannot upgrade Magento or cannot apply the official patches, try this one.
CVE-2022-24086CRITICALunder attack25 Nov 2024
Adobe Commerce checkout improper input validation leads to remote code execution
100RISK
open
previouspage 330 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.