Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
76,559 exploits
GitHub PoC1
chsxthwik/CVE-2024-27954
CVE-2024-27954CRITICAL30 Oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISK
open
GitHub PoC4
Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities
CVE-2024-27954CRITICAL29 Oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISK
open
GitHub PoC23
Exploit for CyberPanel Pre-Auth RCE via Command Injection
CVE-2024-51378CRITICALunder attackransomware29 Oct 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27954CRITICAL29 Oct 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-51378CRITICALunder attackransomware29 Oct 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISK
open
VulnCheck XDB
client-side
CVE-2024-44258HIGH29 Oct 2024
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18
41RISK
open
GitHub PoC
It's Proof of Concept on CVE-2024-24919-POC , i made it after it's discoverd
CVE-2024-24919HIGHunder attackransomware28 Oct 2024
Information disclosure
100RISK
open
GitHub PoC1
0xDTC/Prestashop-CVE-2024-34716
CVE-2024-34716CRITICAL28 Oct 2024
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISK
open
GitHub PoC2
Stack-Overflow on TendaAC8
CVE-2023-33669CRITICAL28 Oct 2024
Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c funct
48RISK
open
Metasploit600
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
CVE-2024-28397MEDIUM28 Oct 2024
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
Metasploit600
Prison Management System 1.0 Authenticated RCE via Unrestricted File Upload
CVE-2024-48594HIGH28 Oct 2024
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the f
36RISK
open
Metasploit600
Pyload RCE (CVE-2024-39205) with js2py sandbox escape (CVE-2024-28397)
CVE-2024-39205CRITICAL28 Oct 2024
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware28 Oct 2024
Information disclosure
100RISK
open
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51378CRITICALunder attackransomware27 Oct 2024
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISK
open
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51568CRITICAL27 Oct 2024
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISK
open
Metasploit600
CyberPanel Multi CVE Pre-auth RCE
CVE-2024-51567CRITICALunder attackransomware27 Oct 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISK
open
GitHub PoC
Refurbish
CVE-2022-0944CRITICAL27 Oct 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC
CVE-2023-41425 Refurbish
CVE-2023-41425MEDIUM27 Oct 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC
Refurbish Chamilo LMS CVE-2023-4220 exploit written in bash
CVE-2023-4220HIGH27 Oct 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH27 Oct 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC
CVE-2019-9053 rewritten in python3 to fix broken syntax. Affects CMS made simple <2.2.10
CVE-2019-905326 Oct 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC18
Pyload RCE with js2py sandbox escape
CVE-2024-39205CRITICAL26 Oct 2024
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RISK
open
GitHub PoC3
Zabbix Frontend Authentication Bypass Vulnerability
CVE-2022-23131CRITICALunder attack25 Oct 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-23131CRITICALunder attack25 Oct 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
VulnCheck XDB
local
CVE-2024-35250HIGHunder attack25 Oct 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
GitHub PoC1
CVE-2022-0944 Remote Code Execution Exploit
CVE-2022-0944CRITICAL25 Oct 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC
tadash10/Detailed-Analysis-and-Mitigation-Strategies-for-CVE-2024-38124-and-CVE-2024-43468
CVE-2024-38124CRITICAL25 Oct 2024
Windows Netlogon Elevation of Privilege Vulnerability
48RISK
open
GitHub PoC13
Cobalt Strike 的 CVE-2024-35250 的 BOF。(请给我加个星,谢谢。)
CVE-2024-35250HIGHunder attack25 Oct 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
VulnCheck XDB
client-side
CVE-2024-37383MEDIUMunder attack24 Oct 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISK
open
GitHub PoC5
Proof of concept for CVE-2024-37383
CVE-2024-37383MEDIUMunder attack24 Oct 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISK
open
previouspage 339 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.