Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
77,151 exploits
GitHub PoC8
Grafana Decryptor for CVE-2021-43798
CVE-2021-43798HIGHunder attack02 Jul 2024
Grafana path traversal
100RISK
open
GitHub PoC
edsonjt81/CVE-2024-6387_Check
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-6387HIGH02 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack02 Jul 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
VulnCheck XDB
initial-access
CVE-2023-39361CRITICAL01 Jul 2024
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISK
open
VulnCheck XDB
initial-access
CVE-2019-1881801 Jul 2024
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
infoleak
CVE-2024-28995HIGHunder attack01 Jul 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1960901 Jul 2024
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RISK
open
VulnCheck XDB
initial-access
CVE-2024-29269HIGH01 Jul 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open
GitHub PoC
jack0we/CVE-2024-6387
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack01 Jul 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
passwa11/cve-2024-6387-poc
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
SSHd cve-2024-6387-poc
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC24
PoC RCE in OpenSSH
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC129
MIRROR of the original 32-bit PoC for CVE-2024-6387 "regreSSHion" by 7etsuo/cve-2024-6387-poc
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC380
32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC33
CVE-2024-28955 Exploitation PoC
CVE-2024-28995HIGHunder attack01 Jul 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALunder attack01 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC9
CosmicSting: critical unauthenticated XXE vulnerability in Adobe Commerce and Magento (CVE-2024-34102)
CVE-2024-34102CRITICALunder attack01 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC
Magento XXE
CVE-2024-34102CRITICALunder attack01 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC1
Atreb92/cve-2024-37762
CVE-2024-37762CRITICAL01 Jul 2024
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code executio
48RISK
open
GitHub PoC
cmsec423/Magento-XXE-CVE-2024-34102
CVE-2024-34102CRITICALunder attack01 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC
HPT-Intern-Task-Submission/CVE-2023-39361
CVE-2023-39361CRITICAL01 Jul 2024
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISK
open
Metasploit600
Geoserver unauthenticated Remote Code Execution
CVE-2024-36401CRITICALunder attack01 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
Case Study: SSHtranger Things (CVE-2019-6111, CVE-2019-6110) in Cisco SD-WAN
CVE-2019-6111MEDIUM01 Jul 2024
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RISK
open
Metasploit600
Authenticated RCE in Splunk (splunk_archiver app)
CVE-2024-36985HIGH01 Jul 2024
Remote Code Execution (RCE) through an external lookup due to “copybuckets.py“ script in the “splunk_archiver“ application in Splunk Enterprise
36RISK
open
GitHub PoC
Exploit script showcasing a mixture of CVE-2019-18818 and CVE-2019-19609 for unauthenticated remote code execution in Strapi CMS.
CVE-2019-1881801 Jul 2024
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
GitHub PoC495
a signal handler race condition in OpenSSH's server (sshd)
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC6
CLI Tool to Check SSH Servers for Vulnerability to CVE-2024-6387
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC35
Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others.
CVE-2024-6387HIGH01 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
previouspage 380 / 2,572next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.