Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,559 exploits
GitHub PoC4
Masamuneee/CVE-2024-4367-Analysis
CVE-2024-4367MEDIUM04 Sep 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
Metasploit600
Wordpress LiteSpeed Cache plugin cookie theft
CVE-2024-44000CRITICAL04 Sep 2024
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
GitHub PoC1
This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.
CVE-2017-5638CRITICALunder attackransomware04 Sep 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-1212CRITICALunder attack04 Sep 2024
LoadMaster Pre-Authenticated OS Command Injection
100RISK
open
GitHub PoC3
Authenticated Code execution
CVE-2023-26785CRITICAL03 Sep 2024
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File
48RISK
open
GitHub PoC1
Raffli-Dev/CVE-2023-41425
CVE-2023-41425MEDIUM03 Sep 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH03 Sep 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHunder attack03 Sep 2024
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
GitHub PoC1
(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
CVE-2023-4220HIGH03 Sep 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC1
Adobe ColdFusion CVE-2023-26360/CVE-2023-29298 自动化实现反弹
CVE-2023-26360HIGHunder attack03 Sep 2024
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
GitHub PoC1
brownpanda29/Cve-2024-38063
CVE-2024-38063CRITICAL03 Sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
ImageMagick 7.1.0-49 vulnerable to Information Disclosure
CVE-2022-44268MEDIUM02 Sep 2024
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack02 Sep 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC
ps-interactive/cve-2024-38063
CVE-2024-38063CRITICAL02 Sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-7029HIGH02 Sep 2024
Command Injection in AVTech AVM1203 (IP Camera)
68RISK
open
GitHub PoC8
This module exploits a vulnerability in the target service identified as CVE-2023-42115.
CVE-2023-42115CRITICAL02 Sep 2024
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
48RISK
open
GitHub PoC30
poc code for CVE-2024-38080
CVE-2024-38080HIGHunder attack01 Sep 2024
Windows Hyper-V Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHunder attack01 Sep 2024
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
Yowise/CVE-2022-26923
CVE-2022-26923HIGHunder attack01 Sep 2024
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL01 Sep 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
VulnCheck XDB
local
CVE-2024-38080HIGHunder attack01 Sep 2024
Windows Hyper-V Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC9
This is a C language program designed to test the Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063). It sends specially crafted IPv6 packets with embedded shellcode to exploit the vulnerability.
CVE-2024-38063CRITICAL01 Sep 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC9
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
CVE-2024-7954CRITICAL01 Sep 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC
Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0
CVE-2024-44812CRITICAL31 Aug 2024
SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the usern
48RISK
open
GitHub PoC25
CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC
CVE-2024-21413CRITICALunder attack31 Aug 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC43
CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)
CVE-2024-38063CRITICAL31 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack31 Aug 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2023-29360HIGHunder attack31 Aug 2024
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨 #Cybersecurity #SOCAnalyst #LetsDefend
CVE-2024-24919HIGHunder attackransomware31 Aug 2024
Information disclosure
100RISK
open
GitHub PoC11
POC for CVE-2023-29360
CVE-2023-29360HIGHunder attack31 Aug 2024
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISK
open
previouspage 354 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.