Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,559 exploits
GitHub PoC140
exploits for CVE-2024-20017
CVE-2024-20017CRITICAL30 Aug 2024
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote cod
60RISK
open
VulnCheck XDB
infoleak
CVE-2024-1071CRITICAL30 Aug 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-6670CRITICALunder attackransomware30 Aug 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware30 Aug 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-7029HIGH30 Aug 2024
Command Injection in AVTech AVM1203 (IP Camera)
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-7120MEDIUM30 Aug 2024
Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection
70RISK
open
GitHub PoC35
sinsinology/CVE-2024-6670
CVE-2024-6670CRITICALunder attackransomware30 Aug 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RISK
open
GitHub PoC23
Proof of concept : CVE-2024-1071: WordPress Vulnerability Exploited
CVE-2024-1071CRITICAL30 Aug 2024
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISK
open
GitHub PoC
A POC demo on CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware30 Aug 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
LuisMateo1/Arbitrary-File-Read-CVE-2024-24919
CVE-2024-24919HIGHunder attackransomware29 Aug 2024
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware29 Aug 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC295
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
CVE-2017-12615HIGHunder attackransomware29 Aug 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC3
CVE-2019-15107 Webmin unauthenticated RCE
CVE-2019-15107CRITICALunder attackransomware29 Aug 2024
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack29 Aug 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware29 Aug 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
VulnCheck XDB
client-side
CVE-2024-5274HIGHunder attack29 Aug 2024
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
76RISK
open
GitHub PoC295
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
CVE-2020-1938CRITICALunder attack29 Aug 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware29 Aug 2024
Information disclosure
100RISK
open
GitHub PoC7
Fully automated PoC - CVE-2024-25641 - RCE - Cacti < v1.2.26 🌵
CVE-2024-25641CRITICAL29 Aug 2024
Cacti RCE vulnerability when importing packages
85RISK
open
GitHub PoC1
In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named "regreSSHion," this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.
CVE-2024-6387HIGH29 Aug 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
Metasploit300
WhatsUp Gold SQL Injection (CVE-2024-6670)
CVE-2024-6670CRITICALunder attackransomware29 Aug 2024
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RISK
open
GitHub PoC83
mistymntncop/CVE-2024-5274
CVE-2024-5274HIGHunder attack29 Aug 2024
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL28 Aug 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC2
D0rDa4aN919/CVE-2023-22809-Exploiter
CVE-2023-22809HIGH28 Aug 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC6
This exploit will attempt to execute system commands on SPIP targets.
CVE-2024-7954CRITICAL28 Aug 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC3
Apache OFBiz CVE-2024-38856
CVE-2024-38856HIGHunder attack28 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
CVE-2024-7593CRITICALunder attack28 Aug 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open
GitHub PoC1
【Teedy 1.11】Account Takeover via XSS
CVE-2024-46278HIGH28 Aug 2024
Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
41RISK
open
GitHub PoC2
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
CVE-2024-6387HIGH28 Aug 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC7
potential memory corruption vulnerabilities in IPv6 networks.
CVE-2024-38063CRITICAL28 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
previouspage 355 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.