Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
76,559 exploits
VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗GitHub PoC
Research
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open ↗Metasploit300
SolarWinds Web Help Desk Backdoor (CVE-2024-28987)
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open ↗GitHub PoC
MLflow LFI/RFI Vulnerability -CVE-2023-1177 - Reproduced
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open ↗VulnCheck XDB
infoleak
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open ↗GitHub PoC★ 3
Proof-of-Concept for CVE-2024-5932 GiveWP PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISK
open ↗GitHub PoC★ 1
CVE-2023-7028 POC && Exploit
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open ↗VulnCheck XDB
local
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RISK
open ↗VulnCheck XDB
initial-access
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open ↗GitHub PoC
A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗VulnCheck XDB
infoleak
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open ↗GitHub PoC
RedTeam-Rediron/CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open ↗VulnCheck XDB
initial-access
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗GitHub PoC
Unauthenticated Remote Code Execution – Bricks
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗GitHub PoC★ 25
PHP CGI Argument Injection (CVE-2024-4577) RCE
Argument Injection in PHP-CGI
100RISK
open ↗GitHub PoC
Reproducing the following CVEs with dockerfile:CVE-2024-33644 CVE-2024-34370 CVE-2024-22120
WordPress Customify Site Library plugin <= 0.0.9 - Remote Code Execution (RCE) vulnerability
48RISK
open ↗GitHub PoC
CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin
WordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.0 is vulnerable to Arbitrary File Upload
48RISK
open ↗GitHub PoC
PoC
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open ↗VulnCheck XDB
infoleak
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open ↗GitHub PoC
adobe commerce
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗VulnCheck XDB
initial-access
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open ↗GitHub PoC★ 1
jeyabalaji711/CVE-2024-42919
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
48RISK
open ↗GitHub PoC
dweger-scripts/CVE-2024-38063-Remediation
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.