Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
76,573 exploits
GitHub PoC★ 2
Perform With Massive Apache OFBiz Zero-Day Scanner & RCE
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗GitHub PoC★ 7
检测RDL服务是否运行,快速排查受影响资产
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 13
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open ↗GitHub PoC★ 2
基于135端口检测目标是否存在CVE-2024-38077漏洞
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 2
A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
48RISK
open ↗GitHub PoC
lworld0x00/CVE-2024-38077-notes
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗VulnCheck XDB
local
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering
33RISK
open ↗GitHub PoC★ 5
it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script automates the process of authorization, payload generation, and execution, allowing for remote command execution on the target device.
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISK
open ↗GitHub PoC★ 13
远程探测 remote desktop licensing 服务开放情况,用于 CVE-2024-38077 漏洞快速排查
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
Calibre Remote Code Execution
85RISK
open ↗GitHub PoC★ 3
CVE-2024-38077,本仓库仅用作备份,
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 1
Sec-Link/CVE-2024-38077
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 1
psl-b/CVE-2024-38077-check
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 9
SecStarBot/CVE-2024-38077-POC
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 223
RDL的堆溢出导致的RCE
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
jtoalu/CTF-CVE-2019-9053-GTFOBins
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗GitHub PoC
elliotosama/CVE-2012-2982
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open ↗GitHub PoC★ 5
it is script designed to interact with a router by sending a payload to its system tools. The script retrieves the router's configuration from environment variables to ensure security. It includes functions for generating an authorization header, sending a payload, and logging the process.
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
53RISK
open ↗Metasploit500
Asterisk AMI Originate Authenticated RCE
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
36RISK
open ↗Metasploit300
Camaleon CMS Directory Traversal CVE-2024-46987
Arbitrary path traversal in Camaleon CMS
61RISK
open ↗GitHub PoC★ 1
An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC★ 1
CVE-2024-41651
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func
48RISK
open ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗GitHub PoC★ 49
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗GitHub PoC
bolkv/CVE-2024-4320
Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
60RISK
open ↗GitHub PoC★ 2
exploit que vulnera Jenkins hecho en Python
ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
48RISK
open ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.