Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,647 exploits
GitHub PoC1
Exploit para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).
CVE-2014-6271CRITICALunder attack14 Jul 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack14 Jul 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire
CVE-2024-6387HIGH14 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
Phantom-IN/CVE-2024-34102
CVE-2024-34102CRITICALunder attack14 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC5
Exploitation CVE-2024-34102
CVE-2024-34102CRITICALunder attack13 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC1
CVE-2024-39250 TimeTrax SQLi
CVE-2024-39250CRITICAL13 Jul 2024
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t
63RISK
open
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALunder attack13 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC76
CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit
CVE-2024-41570CRITICAL13 Jul 2024
An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALunder attack13 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack12 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack12 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack12 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC
BlackFrog-hub/cve-2015-1328
CVE-2015-132812 Jul 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC
jakabakos/CVE-2024-36401-GeoServer-RCE
CVE-2024-36401CRITICALunder attack12 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC10
Bulk scanning tool for ServiceNow CVE-2024-4879 vulnerability
CVE-2024-4879CRITICALunder attack12 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC26
CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow
CVE-2024-4879CRITICALunder attack12 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack12 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC4
CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
CVE-2024-4879CRITICALunder attack12 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC
ThinkAdmin v5 v6 任意文件读取漏洞利用,可自定义字典爆破
CVE-2020-2554011 Jul 2024
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISK
open
GitHub PoC5
ATTACK PoC - PHP CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware11 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH11 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC8
Perform with massive Wordpress SQLI 2 RCE
CVE-2024-27956CRITICAL11 Jul 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware11 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Examining the phases of an attack using “Dragonfish's Elise Malware”, specifically, exploring the exploitation of vulnerability CVE-2017-11882.
CVE-2017-11882HIGHunder attackransomware11 Jul 2024
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL11 Jul 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack11 Jul 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
CVE-2023–4220 Exploit
CVE-2023-4220HIGH11 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware11 Jul 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC1
OpenSSH vulnerability CVE-2024-6387
CVE-2024-6387HIGH11 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC3
This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware blocks HTTP requests containing specific patterns, and the vulnerability checker tests for and exploits the Apache Struts 2 vulnerability (CVE-2017-5638).
CVE-2017-5638CRITICALunder attackransomware11 Jul 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
previouspage 369 / 2,555next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.