Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
76,647 exploits
GitHub PoC
CosmicSting (CVE-2024-34102) POC / Patch Validator
CVE-2024-34102CRITICALunder attack07 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC1
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC1
RCE Chamilo 1.11.24
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALunder attack07 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC1
Chamilo LMS Unauthenticated Remote Code Execution
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC5
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware06 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
GitHub PoC7
PoC - PHP CGI Argument Injection CVE-2024-4577 (Scanner and Exploit)
CVE-2024-4577CRITICALunder attackransomware06 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack06 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC56
Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit
CVE-2024-36401CRITICALunder attack06 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC44
该漏洞存在于 NtQueryInformationToken 函数中,特别是在处理AuthzBasepCopyoutInternalSecurityAttributes 函数时,该漏洞源于内核在操作对象时对锁定机制的不当管理,这一失误可能导致恶意实体意外提升权限。
CVE-2024-30088HIGHunder attackransomware05 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC1
Exploiter a Vulnerability detection and Exploitation tool for GeoServer Unauthenticated Remote Code Execution CVE-2024-36401.
CVE-2024-36401CRITICALunder attack05 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack05 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC375
HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the Web interface Version 3.1.3.150324 + CVE-2021-36260 Detection
CVE-2021-36260CRITICALunder attack05 Jul 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack05 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware05 Jul 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC1
TeamCity RCE for Linux (CVE-2023-42793)
CVE-2023-42793CRITICALunder attackransomware05 Jul 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALunder attack05 Jul 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
puckiestyle/CVE-2023-27532-RCE-Only
CVE-2023-27532HIGHunder attackransomware05 Jul 2024
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISK
open
GitHub PoC59
GNU IFUNC is the real culprit behind CVE-2024-3094
CVE-2024-3094CRITICAL05 Jul 2024
Xz: malicious code in distributed source
70RISK
open
previouspage 371 / 2,555next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.