Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
76,647 exploits
GitHub PoC4
lala-amber/CVE-2024-6387
CVE-2024-6387HIGH04 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC4
SentinelSSH is an advanced, high-performance SSH vulnerability scanner written in Go. It's specifically designed to detect the CVE-2024-6387 vulnerability in OpenSSH servers across various network environments.
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC22
Targeting a signal handler race condition in OpenSSH's server (sshd) on glibc-based Linux systems.
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC3
SSH Exploit for CVE-2024-6387 : RCE in OpenSSH's server, on glibc-based Linux systems
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
CVE-2024-39844 (ZNC < 1.9.1 modtcl RCE)
CVE-2024-39844CRITICAL03 Jul 2024
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
48RISK
open
GitHub PoC
jocker2410/CVE-2024-6387_poc
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
Redfox-Security/Unveiling-Moniker-Link-CVE-2024-21413-Navigating-the-Latest-Cybersecurity-Landscape
CVE-2024-21413CRITICALunder attack03 Jul 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
t3rry327/cve-2024-6387-poc
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC6
Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC) BlueBorne - Proof of Concept - Unarmed/Unweaponized - DoS (Crash) only
CVE-2017-100025103 Jul 2024
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RISK
open
GitHub PoC
CVE-2024-4577 EXP
CVE-2024-4577CRITICALunder attackransomware03 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
PoC Exploit for CVE-2024-5084
CVE-2024-5084CRITICAL03 Jul 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
GitHub PoC
CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523
CVE-2017-0144HIGHunder attackransomware03 Jul 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523
CVE-2011-252303 Jul 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware03 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack02 Jul 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-27292HIGH02 Jul 2024
Docassemble unauthorized access through URL manipulation
68RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack02 Jul 2024
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack02 Jul 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
openssh-cve-2024-6387.sh
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC3
CVE-2024-6387-Check is a streamlined and efficient tool created to detect servers operating on vulnerable versions of OpenSSH.
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
edsonjt81/CVE-2024-6387_Check
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC2
regreSSHion vulnerability in OpenSSH CVE-2024-6387 Testing Script
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC10
CVE-2024-6387 with auto ip scanner and auto expliot
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC4
CVE-2024-6387 : Vulnerability Detection tool for regreSSHion Remote Unauthenticated Code Execution in OpenSSH Server
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
An Ansible Playbook to mitigate the risk of RCE (CVE-2024-6387) until platforms update OpenSSH to a non-vulnerable version.
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
A bash script for nmap to scan for vulnerable machines in regards to the latest CVE-2024-6387
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
Test_CVE-2024-6387 is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack02 Jul 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC
fork for proof of concept of the regresshion vulnerability
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
previouspage 373 / 2,555next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.