Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
76,559 exploits
GitHub PoC
idkwastaken/CVE-2024-38063
CVE-2024-38063CRITICAL14 Oct 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack14 Oct 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
client-side
CVE-2023-6000MEDIUM14 Oct 2024
Popup Builder < 4.2.3 - Unauthenticated Stored XSS
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-1698CRITICAL14 Oct 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware14 Oct 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware14 Oct 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
kkhackz0013/CVE-2024-36401
CVE-2024-36401CRITICALunder attack14 Oct 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC9
PoC for the Untrusted Pointer Dereference in the ks.sys driver
CVE-2024-35250HIGHunder attack14 Oct 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
GitHub PoC1
PoC for RCE in SQLPad (CVE-2022-0944)
CVE-2022-0944CRITICAL13 Oct 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC
Gilospy/CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware13 Oct 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
lemonadern/poc-cve-2019-14287
CVE-2019-1428713 Oct 2024
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
local
CVE-2024-35250HIGHunder attack13 Oct 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1591613 Oct 2024
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system
23RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware13 Oct 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-7593CRITICALunder attack12 Oct 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-40539CRITICALunder attackransomware12 Oct 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-40539CRITICALunder attackransomware12 Oct 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-8529CRITICAL12 Oct 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RISK
open
GitHub PoC1
CVE-2021-40539:ADSelfService Plus RCE漏洞
CVE-2021-40539CRITICALunder attackransomware12 Oct 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
GitHub PoC
CVE-2021-40539:ADSelfService Plus RCE漏洞
CVE-2021-40539CRITICALunder attackransomware12 Oct 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
GitHub PoC
intel365/CVE-2024-7593
CVE-2024-7593CRITICALunder attack12 Oct 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open
GitHub PoC2
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
CVE-2024-8529CRITICAL12 Oct 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RISK
open
GitHub PoC1
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
CVE-2024-9707CRITICAL11 Oct 2024
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RISK
open
GitHub PoC
Checkpoint SQL Injection via Time-Based Attack (CVE-2024-9465)
CVE-2024-9465CRITICALunder attack11 Oct 2024
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9707CRITICAL11 Oct 2024
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RISK
open
GitHub PoC1
test_private_CVE
CVE-2024-23113CRITICALunder attack11 Oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open
GitHub PoC1
OxLmahdi/cve-2024-5932
CVE-2024-5932CRITICAL11 Oct 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL10 Oct 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
GitHub PoC2
intel365/CVE-2024-29973
CVE-2024-29973CRITICAL10 Oct 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
GitHub PoC5
is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies
CVE-2024-44000CRITICAL10 Oct 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
previouspage 344 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.