Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
76,559 exploits
GitHub PoC
1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover
CVE-2024-50478CRITICAL05 Nov 2024
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
48RISK
open
GitHub PoC4
This repository contains a Crystallographic Information File (CIF) intended for use on the "Chemistry" machine on Hack The Box (HTB).
CVE-2024-23346CRITICAL05 Nov 2024
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open
GitHub PoC2
Meetup <= 0.1 - Authentication Bypass via Account Takeover
CVE-2024-50483CRITICAL05 Nov 2024
WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
48RISK
open
GitHub PoC
Signup Page <= 1.0 - Unauthenticated Arbitrary Options Update
CVE-2024-50475CRITICAL04 Nov 2024
WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISK
open
GitHub PoC
GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update
CVE-2024-50476CRITICAL04 Nov 2024
WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-50498CRITICAL04 Nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open
GitHub PoC3
WP Query Console <= 1.0 - Unauthenticated Remote Code Execution
CVE-2024-50498CRITICAL04 Nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open
GitHub PoC
Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)
CVE-2024-37383MEDIUMunder attack03 Nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISK
open
GitHub PoC
ahmetramazank/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware03 Nov 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
client-side
CVE-2024-37383MEDIUMunder attack03 Nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISK
open
GitHub PoC
77Philly/CVE-2024-7456scripts
CVE-2024-7456CRITICAL02 Nov 2024
SQL Injection in lunary-ai/lunary
48RISK
open
GitHub PoC1
JAckLosingHeart/CVE-2024-51132-POC
CVE-2024-51132CRITICAL02 Nov 2024
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information o
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH02 Nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC
POC firewall with rules designed to detect and block Spring4Shell vulnerability (CVE-2022-22965) exploit
CVE-2022-22965CRITICALunder attack02 Nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
CVE-2023-4220 Chamilo Exploit
CVE-2023-4220HIGH02 Nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC2
wp/ultimate-member - SQL Injection Vulnerability Exploit Script.
CVE-2024-1071CRITICAL01 Nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISK
open
VulnCheck XDB
client-side
CVE-2015-925101 Nov 2024
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RISK
open
VulnCheck XDB
infoleak
CVE-2024-1071CRITICAL01 Nov 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-51567CRITICALunder attackransomware31 Oct 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISK
open
GitHub PoC
GodOfServer/CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware31 Oct 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
hualy13/CVE-2019-0708-Check
CVE-2019-0708CRITICALunder attackransomware31 Oct 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23113CRITICALunder attack31 Oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open
GitHub PoC5
CVE-2024-51567 is a Python PoC exploit targeting an RCE vulnerability in CyberPanel v2.3.6’s upgrademysqlstatus endpoint, bypassing CSRF protections.
CVE-2024-51567CRITICALunder attackransomware31 Oct 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISK
open
GitHub PoC1
puckiestyle/CVE-2024-23113
CVE-2024-23113CRITICALunder attack31 Oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open
VulnCheck XDB
infoleak
CVE-2021-3129CRITICALunder attackransomware31 Oct 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-27954CRITICAL30 Oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISK
open
GitHub PoC1
CVE-2024-48359 PoC
CVE-2024-48359CRITICAL30 Oct 2024
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parame
48RISK
open
GitHub PoC2
sxyrxyy/CVE-2024-21320-POC
CVE-2024-21320MEDIUM30 Oct 2024
Windows Themes Spoofing Vulnerability
38RISK
open
GitHub PoC
Writing one because the one I found isn't working
CVE-2023-41425MEDIUM30 Oct 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC1
chsxthwik/CVE-2024-27954
CVE-2024-27954CRITICAL30 Oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISK
open
previouspage 338 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.