Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,896cataloged exploits
35,202CVEs with public exploitation
24,695lab-tested
76,559 exploits
VulnCheck XDB
infoleak
CVE-2024-27564MEDIUM15 Sep 2024
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RISK
open
GitHub PoC5
A Bash script for Kali Linux that exploits an iOS WebKit vulnerability (CVE-2020-27950) using Metasploit and ngrok. Automates payload delivery with a public URL via ngrok, checks for required tools, handles errors, and provides an easy way to crash browsers for educational purposes only.
CVE-2020-27950MEDIUMunder attack15 Sep 2024
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RISK
open
GitHub PoC48
POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692
CVE-2024-23692CRITICALunder attackransomware15 Sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
GitHub PoC2
dogucyber/WordPress-Exploit-CVE-2024-1071
CVE-2024-1071CRITICAL15 Sep 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISK
open
GitHub PoC54
Pre-Auth Exploit for CVE-2024-40711
CVE-2024-40711CRITICALunder attackransomware15 Sep 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISK
open
GitHub PoC1
Unauthenticated remote code execution via Calibre’s content server in Calibre <= 7.14.0.
CVE-2024-6782CRITICAL15 Sep 2024
Calibre Remote Code Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL15 Sep 2024
Code Injection in pyload/pyload
85RISK
open
GitHub PoC
New exploit for pyLoad v0.5.0 - Unauthenticated remote code excecution
CVE-2023-0297CRITICAL15 Sep 2024
Code Injection in pyload/pyload
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-1071CRITICAL15 Sep 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attackransomware15 Sep 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL14 Sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-8503CRITICAL14 Sep 2024
VICIdial Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack14 Sep 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC19
Exploit for CVE-2024-29847
CVE-2024-29847CRITICAL14 Sep 2024
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows
60RISK
open
GitHub PoC2
chsxthwik/CVE-2024-2876
CVE-2024-2876CRITICAL14 Sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC2
Robocopsita/CVE-2022-0944_RCE_POC
CVE-2022-0944CRITICAL13 Sep 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC
0xWhoami35/CVE-2024-4879
CVE-2024-4879CRITICALunder attack13 Sep 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack13 Sep 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack13 Sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
sshipanoo/CVE-2024-44542
CVE-2024-44542CRITICAL13 Sep 2024
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.
48RISK
open
GitHub PoC
acidburn2049/CVE-2021-3156
CVE-2021-3156HIGHunder attack13 Sep 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
Proof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1
CVE-2024-36401CRITICALunder attack13 Sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker successfully bypassed authentication, gaining admin control over the device! Immediate containment was critical. Stay vigilant! 💻🔐
CVE-2023-20198CRITICALunder attack13 Sep 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3383113 Sep 2024
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute
43RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 Sep 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)
CVE-2024-1709CRITICALunder attackransomware12 Sep 2024
Authentication bypass using an alternate path or channel
100RISK
open
GitHub PoC
Event ID 189 Rule Name SOC227 Microsoft SharePoint Server Elevation of Privilege Possible CVE-2023-29357 .. Exploitation
CVE-2023-29357CRITICALunder attackransomware12 Sep 2024
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
CVE-2024-8277 - 0Day Auto Exploit Authentication Bypass in WooCommerce Photo Reviews Plugin
CVE-2024-8277CRITICAL12 Sep 2024
WooCommerce Photo Reviews Premium <= 1.3.13.2 - Authentication Bypass to Account Takeover and Privilege Escalation
48RISK
open
GitHub PoC
Old weaponized CVE-2022-1388 exploit.
CVE-2022-1388CRITICALunder attackransomware12 Sep 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware12 Sep 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
previouspage 351 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.