Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
77,151 exploits
VulnCheck XDB
denial-of-service
CVE-2023-29552HIGHunder attack04 Jul 2024
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.
83RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack04 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
CVE-2017-12617
CVE-2017-12617HIGHunder attack04 Jul 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
VulnCheck XDB
local
CVE-2024-1086HIGHunder attackransomware04 Jul 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack04 Jul 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack04 Jul 2024
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware03 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523
CVE-2017-0144HIGHunder attackransomware03 Jul 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
CVE-2024-4577 EXP
CVE-2024-4577CRITICALunder attackransomware03 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
CVE-2024-39844 (ZNC < 1.9.1 modtcl RCE)
CVE-2024-39844CRITICAL03 Jul 2024
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
48RISK
open
GitHub PoC
CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523
CVE-2011-252303 Jul 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC22
Targeting a signal handler race condition in OpenSSH's server (sshd) on glibc-based Linux systems.
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
t3rry327/cve-2024-6387-poc
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
PoC Exploit for CVE-2024-5084
CVE-2024-5084CRITICAL03 Jul 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
GitHub PoC
jocker2410/CVE-2024-6387_poc
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
Redfox-Security/Unveiling-Moniker-Link-CVE-2024-21413-Navigating-the-Latest-Cybersecurity-Landscape
CVE-2024-21413CRITICALunder attack03 Jul 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
SSH Exploit for CVE-2024-6387 : RCE in OpenSSH's server, on glibc-based Linux systems
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC4
SentinelSSH is an advanced, high-performance SSH vulnerability scanner written in Go. It's specifically designed to detect the CVE-2024-6387 vulnerability in OpenSSH servers across various network environments.
CVE-2024-6387HIGH03 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC6
Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC) BlueBorne - Proof of Concept - Unarmed/Unweaponized - DoS (Crash) only
CVE-2017-100025103 Jul 2024
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RISK
open
GitHub PoC4
CVE-2024-6387-nmap
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
edsonjt81/CVE-2024-6387_Check
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC4
CVE-2024-6387 : Vulnerability Detection tool for regreSSHion Remote Unauthenticated Code Execution in OpenSSH Server
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
raymontag/CVE-2019-2215
CVE-2019-2215HIGHunder attack02 Jul 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC113
PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC3
CVE-2024-6387-Check is a streamlined and efficient tool created to detect servers operating on vulnerable versions of OpenSSH.
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC10
Quickly identifies servers vulnerable to OpenSSH 'regreSSHion' (CVE-2024-6387).
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
dawnl3ss/CVE-2024-6387
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
开箱即用的AK47
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC66
CVE-2024-6387 (regreSSHion) Exploit (PoC), a vulnerability in OpenSSH's server (sshd) on glibc-based Linux systems.
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC2
regreSSHion vulnerability in OpenSSH CVE-2024-6387 Testing Script
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
previouspage 378 / 2,572next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.