Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,894cataloged exploits
35,202CVEs with public exploitation
24,695lab-tested
76,559 exploits
VulnCheck XDB
initial-access
CVE-2023-47253CRITICAL19 Sep 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISK
open
GitHub PoC
Webrun <= 3.6.0.42 SQLi
CVE-2021-4365019 Sep 2024
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RISK
open
GitHub PoC
poc of cve-2024-8752(WebIQ 2.15.9)
CVE-2024-8752CRITICAL19 Sep 2024
WebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
68RISK
open
GitHub PoC
CVE-2023-47253 | Qualitor <= 8.20 RCE
CVE-2023-47253CRITICAL19 Sep 2024
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques
68RISK
open
GitHub PoC6
POC_CVE-2024-46256
CVE-2024-46256CRITICAL19 Sep 2024
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISK
open
GitHub PoC
MLFlow Path Traversal
CVE-2023-1177CRITICAL19 Sep 2024
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
GitHub PoC2
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
CVE-2024-8522CRITICAL19 Sep 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RISK
open
GitHub PoC4
CVE-2022-23131 Zabbix Server SAML authentication exploit
CVE-2022-23131CRITICALunder attack18 Sep 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC
safeer-accuknox/CrushFTP-cve-2024-4040-poc
CVE-2024-4040CRITICALunder attack18 Sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALunder attack18 Sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALunder attack18 Sep 2024
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open
GitHub PoC3
Client Implementation for the WatchGuard SSO Agent Protocol used for Security Research (CVE-2024-6592, CVE-2024-6593, CVE-2024-6594)
CVE-2024-6592CRITICAL17 Sep 2024
WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
48RISK
open
GitHub PoC2
The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads
CVE-2024-43160CRITICAL17 Sep 2024
WordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
63RISK
open
GitHub PoC2
0xAgun/CVE-2024-2876
CVE-2024-2876CRITICAL17 Sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL17 Sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC49
This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64.
CVE-2024-7965HIGHunder attack16 Sep 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RISK
open
VulnCheck XDB
infoleak
CVE-2016-1092416 Sep 2024
The ebook-download plugin before 1.2 for WordPress has directory traversal.
43RISK
open
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL16 Sep 2024
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-8190HIGHunder attack16 Sep 2024
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RISK
open
VulnCheck XDB
initial-access
CVE-2024-44000CRITICAL16 Sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
GitHub PoC
Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!
CVE-2021-3493HIGHunder attack16 Sep 2024
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC1
PoC code for vulnerability in webmod v0.48. Originally written in 2007, assigned CVE-2007-1260.
CVE-2007-126016 Sep 2024
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RISK
open
GitHub PoC16
CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection
CVE-2024-8190HIGHunder attack16 Sep 2024
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo
93RISK
open
GitHub PoC3
CVE-2024-44000-LiteSpeed-Cache
CVE-2024-44000CRITICAL16 Sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
GitHub PoC4
Server-Side Template Injection Exploit
CVE-2024-32651CRITICAL16 Sep 2024
Server Side Template Injection in Jinja2 allows Remote Command Execution
85RISK
open
VulnCheck XDB
client-side
CVE-2024-7965HIGHunder attack16 Sep 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RISK
open
GitHub PoC4
Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption
CVE-2023-21716CRITICAL16 Sep 2024
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC54
Pre-Auth Exploit for CVE-2024-40711
CVE-2024-40711CRITICALunder attackransomware15 Sep 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISK
open
GitHub PoC48
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
CVE-2024-23692CRITICALunder attackransomware15 Sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attackransomware15 Sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
previouspage 350 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.