Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,559 exploits
GitHub PoC7
potential memory corruption vulnerabilities in IPv6 networks.
CVE-2024-38063CRITICAL28 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
CVE-2024-6387HIGH28 Aug 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC6
This exploit will attempt to execute system commands on SPIP targets.
CVE-2024-7954CRITICAL28 Aug 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
CVE-2024-7593CRITICALunder attack28 Aug 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open
GitHub PoC4
Jelly Template Injection Vulnerability in ServiceNow | POC CVE-2024-4879
CVE-2024-4879CRITICALunder attack27 Aug 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC
CVE-2023-4220 Chamilo Exploit
CVE-2023-4220HIGH27 Aug 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC10
CVE-2024-25641 - RCE Automated Exploit - Cacti 1.2.26
CVE-2024-25641CRITICAL27 Aug 2024
Cacti RCE vulnerability when importing packages
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL27 Aug 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open
GitHub PoC7
PoC for the CVE-2024 Litespeed Cache Privilege Escalation
CVE-2024-28000CRITICAL27 Aug 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open
GitHub PoC2
CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
CVE-2023-41425MEDIUM27 Aug 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC4
Mass scanner for CVE-2024-36401
CVE-2024-36401CRITICALunder attack27 Aug 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC1
Nuclei template to scan for Apache Ofbiz affecting versions before 18.12.15
CVE-2024-38856HIGHunder attack27 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC2
PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26
CVE-2024-25641CRITICAL27 Aug 2024
Cacti RCE vulnerability when importing packages
85RISK
open
GitHub PoC
zxybfq/CVE-2021-4034
CVE-2021-4034HIGHunder attack27 Aug 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack27 Aug 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack27 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC20
patchpoint/CVE-2024-38063
CVE-2024-38063CRITICAL27 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack27 Aug 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
Metasploit600
Moodle Remote Code Execution (CVE-2024-43425)
CVE-2024-43425HIGH27 Aug 2024
Moodle: remote code execution via calculated question types
78RISK
open
GitHub PoC
Sudo Privilege Escalation: CVE-2023-22809 Simulation This project simulates the Sudo privilege escalation vulnerability (CVE-2023-22809) to demonstrate how unauthorized root access can be gained. It involves identifying and exploiting this vulnerability in a controlled environment using Parrot OS, the Sudo command, and Bash scripting.
CVE-2023-22809HIGH26 Aug 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware26 Aug 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
RCE OpenSSH CVE-2024-6387 Check and Exploit
CVE-2024-6387HIGH26 Aug 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack26 Aug 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC
CVE-2024-45265
CVE-2024-45265CRITICAL26 Aug 2024
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to exe
48RISK
open
GitHub PoC8
This repository automates the process of exploiting CVE-2024-25641 on Cacti 1.2.26
CVE-2024-25641CRITICAL26 Aug 2024
Cacti RCE vulnerability when importing packages
85RISK
open
GitHub PoC
sanan2004/CVE-2023-20198
CVE-2023-20198CRITICALunder attack26 Aug 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware26 Aug 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Apache-HTTP-Server-2.4.50-RCE This tool is designed to test Apache servers for the CVE-2021-41773 / CVE-2021-42013 vulnerability. It is intended for educational purposes only and should be used responsibly on systems you have explicit permission to test.
CVE-2021-41773HIGHunder attackransomware26 Aug 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware26 Aug 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
POC & Lab For CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware26 Aug 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 356 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.