Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
76,559 exploits
VulnCheck XDB
infoleak
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗GitHub PoC★ 1
ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
Privilege Escalation
41RISK
open ↗GitHub PoC★ 42
p33d/CVE-2024-45519
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open ↗GitHub PoC★ 1
GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗VulnCheck XDB
initial-access
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open ↗VulnCheck XDB
infoleak
CVE-2024-38816: Path traversal vulnerability in functional web frameworks
61RISK
open ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗GitHub PoC★ 1
Proof of Concept for CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC
This is a demo for CVE-2024-32002 POC
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC
This is a demo for CVE-2024-32002 POC
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC★ 1
This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a **malicious RAR archive** that triggers the execution of arbitrary code when the victim opens a benign-looking file within the archive (such as a PDF).
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗GitHub PoC
Reproduction of SQL Injection Vulnerabilities in OpenHIS
SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the
48RISK
open ↗VulnCheck XDB
client-side
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗VulnCheck XDB
infoleak
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISK
open ↗GitHub PoC★ 5
A proof of concept of traefik CVE to understand the impact
HTTP client can remove the X-Forwarded headers in Traefik
48RISK
open ↗GitHub PoC★ 3
A vulnerability scanner that searches for the CVE-2024-9166 vulnerability on websites, more info about this vulnerability here: https://www.tenable.com/cve/CVE-2024-9166
OS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
63RISK
open ↗GitHub PoC★ 8
Pgadmin4 Sensitive Information Exposure
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISK
open ↗GitHub PoC
p33d/CVE-2024-8275
The Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
60RISK
open ↗GitHub PoC
d
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗GitHub PoC★ 5
PrusaSlicer Arbitrary Code Execution using .3mf
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RISK
open ↗Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
libppd's ppdCreatePPDFromIPP2 function does not sanitize IPP attributes when creating the PPD buffer
48RISK
open ↗Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
libcupsfilters's cfGetPrinterAttributes5 does not validate IPP attributes returned from an IPP server
58RISK
open ↗Metasploit300
CUPS IPP Attributes LAN Remote Code Execution
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗GitHub PoC
CVE-2024-46627 - Incorrect access control in BECN DATAGERRY v2.2 allows attackers to > execute arbitrary commands via crafted web requests.
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
63RISK
open ↗Metasploit300
WordPress TI WooCommerce Wishlist SQL Injection (CVE-2024-43917)
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open ↗GitHub PoC
CVE-2019-15107 webmin 취약점에 대해서 직접 서버를 구축하고 공격 결과를 남긴 정보입니다.
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open ↗VulnCheck XDB
client-side
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.