Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,607cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
76,558 exploits
GitHub PoC
p33d/Palo-Alto-Expedition-Remote-Code-Execution-Exploit-CVE-2024-5910-CVE-2024-9464
CVE-2024-5910CRITICALunder attack15 Nov 2024
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-52301HIGH15 Nov 2024
Laravel allows environment manipulation via query string
53RISK
open
GitHub PoC12
Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.
CVE-2024-54756CRITICAL15 Nov 2024
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALunder attack15 Nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL15 Nov 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC1
CVE-2024-54761 PoC
CVE-2024-54761MEDIUM15 Nov 2024
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RISK
open
Metasploit600
LibreNMS Authenticated RCE (CVE-2024-51092)
CVE-2024-51092CRITICAL15 Nov 2024
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr
43RISK
open
Metasploit600
WordPress WP Time Capsule Arbitrary File Upload to RCE
CVE-2024-8856CRITICAL15 Nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
Metasploit600
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
CVE-2024-10924CRITICAL14 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-27997CRITICALunder attackransomware14 Nov 2024
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC2
Bash script to automate Local File Inclusion (LFI) attacks on aiohttp server version 3.9.1.
CVE-2024-23334MEDIUM14 Nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM14 Nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC1
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions leads to (RCE)
CVE-2024-52302HIGH14 Nov 2024
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
41RISK
open
GitHub PoC
CiscoRV320Dump CVE-2019-1653 - Automatition.
CVE-2019-1653HIGHunder attack14 Nov 2024
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
GitHub PoC
Fortigate SSL VPN buffer overflow exploit
CVE-2023-27997CRITICALunder attackransomware14 Nov 2024
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-1653HIGHunder attack14 Nov 2024
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
GitHub PoC4
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass
CVE-2024-10924CRITICAL14 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
CVE-2024-10914_Manual testing with burpsuite
CVE-2024-10914CRITICAL13 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
https://nvd.nist.gov/vuln/detail/CVE-2023-4220
CVE-2023-4220HIGH13 Nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC
Ivanti Cloud Services Appliance - Path Traversal
CVE-2024-8963CRITICALunder attack13 Nov 2024
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISK
open
GitHub PoC2
working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln
CVE-2021-21425CRITICAL13 Nov 2024
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISK
open
GitHub PoC1
Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability
CVE-2024-21534CRITICAL13 Nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RISK
open
GitHub PoC
This script is specifically designed to solve the challenge on PentesterLab for the CVE-2013-0156 exploit
CVE-2013-015613 Nov 2024
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack13 Nov 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command
CVE-2021-3156HIGHunder attack13 Nov 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-8069MEDIUMunder attack13 Nov 2024
Limited remote code execution with privilege of a NetworkService Account access
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-8963CRITICALunder attack13 Nov 2024
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH13 Nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL13 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
previouspage 335 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.