Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
76,647 exploits
GitHub PoC
Wytchwulf/CVE-2015-1397-Magento-Shoplift
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISK
open ↗VulnCheck XDB
initial-access
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗VulnCheck XDB
initial-access
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open ↗VulnCheck XDB
initial-access
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RISK
open ↗GitHub PoC★ 2
Proof Of Concept for CVE-2024-1874
Command injection via array-ish $command parameter of proc_open()
60RISK
open ↗GitHub PoC★ 4
Vulnerability checking tool via Nmap Scripting Engine
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗VulnCheck XDB
initial-access
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗GitHub PoC★ 1
Script para eliminar vulnerabilidad de openssh de ubuntu 22.04 LTS
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open ↗GitHub PoC★ 43
geoserver CVE-2024-36401漏洞利用工具
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗GitHub PoC★ 3
Exploit for CVE-2024-31989.
ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache
48RISK
open ↗VulnCheck XDB
initial-access
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open ↗GitHub PoC★ 1
Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
Automated PHP remote code execution scanner for CVE-2024-4577
Argument Injection in PHP-CGI
100RISK
open ↗GitHub PoC
khanhtranngoccva/cve-2023-38831-poc
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗VulnCheck XDB
initial-access
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open ↗GitHub PoC
Laravel Debug Mode and Payload
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open ↗GitHub PoC
On October 4, 2021, Apache HTTP Server Project released Security advisory on a Path traversal and File disclosure vulnerability in Apache HTTP Server 2.4.49 and 2.4.50 tracked as CVE-2021-41773 and CVE-2021-42013. In the advisory, Apache also highlighted “the issue is known to be exploited in the wild” and later it was identified that the vulnerabi
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗VulnCheck XDB
initial-access
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC★ 3
OpenSSH RCE Massive Vulnerable Scanner
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC★ 525
Kernel exploit for Xbox SystemOS using CVE-2024-30088
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open ↗VulnCheck XDB
initial-access
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open ↗GitHub PoC
LMS Chamilo 1.11.24 CVE-2023-4220 Exploit
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC
OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.