Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,894cataloged exploits
35,202CVEs with public exploitation
24,695lab-tested
76,559 exploits
VulnCheck XDB
initial-access
CVE-2024-7593CRITICALunder attack24 Sep 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALunder attack24 Sep 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open
GitHub PoC9
CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]
CVE-2024-7593CRITICALunder attack24 Sep 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open
GitHub PoC7
Proof of Concept Exploit for CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVE-2024-28987CRITICALunder attack24 Sep 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open
GitHub PoC3
WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution to RCE
CVE-2024-43918CRITICAL24 Sep 2024
WordPress WBW Product Table PRO plugin <= 1.9.4 - Unauthenticated Arbitrary SQL Query Execution vulnerability
48RISK
open
GitHub PoC4
Proof-of-Concept for CVE-2024-47066
CVE-2024-47066CRITICAL24 Sep 2024
Lobe Chat has insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
53RISK
open
GitHub PoC2
vidura2/CVE-2024-46377
CVE-2024-46377CRITICAL23 Sep 2024
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL23 Sep 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC5
TheCyberguy-17/RCE_CVE-2024-7954
CVE-2024-7954CRITICAL23 Sep 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC2
vidura2/CVE-2024-46451
CVE-2024-46451CRITICAL22 Sep 2024
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the de
48RISK
open
GitHub PoC3
vidura2/CVE-2024-46986
CVE-2024-46986CRITICAL22 Sep 2024
Arbitrary file write leading to RCE in Camaleon CMS
75RISK
open
GitHub PoC
WonderCMS RCE CVE-2023-41425
CVE-2023-41425MEDIUM21 Sep 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC
Kode Eksploitasi CVE-2024-38063
CVE-2024-38063CRITICAL21 Sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC3
Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053
CVE-2019-905321 Sep 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
CVE-2024-3273 - D-Link Remote Code Execution (RCE)
CVE-2024-3273HIGHunder attack21 Sep 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3273HIGHunder attack21 Sep 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL20 Sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC
yashfren/CVE-2014-0160-HeartBleed
CVE-2014-0160HIGHunder attack20 Sep 2024
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack20 Sep 2024
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware20 Sep 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
btar1gan/exploit_CVE-2022-35914
CVE-2022-35914CRITICALunder attack20 Sep 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMunder attack20 Sep 2024
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC
MAHajian/CVE-2019-9978
CVE-2019-9978MEDIUMunder attack20 Sep 2024
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC1
teamcity-exploit-cve-2023-42793
CVE-2023-42793CRITICALunder attackransomware20 Sep 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
MLFlow Path Traversal
CVE-2023-1177CRITICAL19 Sep 2024
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
GitHub PoC6
POC_CVE-2024-46256
CVE-2024-46256CRITICAL19 Sep 2024
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-8752CRITICAL19 Sep 2024
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RISK
open
GitHub PoC
CVE-2023-47253 | Qualitor <= 8.20 RCE
CVE-2023-47253CRITICAL19 Sep 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISK
open
GitHub PoC
poc of cve-2024-8752(WebIQ 2.15.9)
CVE-2024-8752CRITICAL19 Sep 2024
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RISK
open
GitHub PoC
Webrun <= 3.6.0.42 SQLi
CVE-2021-4365019 Sep 2024
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RISK
open
previouspage 349 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.