Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
77,151 exploits
GitHub PoC★ 1
CocoaPods RCE Vulnerability CVE-2024-38366
CoacoaPods trunk RCE in email verification system rfc-822
53RISK
open ↗VulnCheck XDB
remote-with-credentials
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open ↗GitHub PoC★ 8
🆘New Windows Kernel Priviledge Escalation Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open ↗GitHub PoC
ArturArz1/TestCVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC★ 31
POC for CVE-2024-34102. A pre-authentication XML entity injection issue in Magento / Adobe Commerce.
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC★ 14
CVE-2024-34102: Unauthenticated Magento XXE
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC
This is a simple proof of concept for CVE-2023-49103.
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISK
open ↗VulnCheck XDB
infoleak
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗VulnCheck XDB
initial-access
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISK
open ↗VulnCheck XDB
infoleak
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC★ 95
A Pwn2Own 2024 SpiderMonkey JIT Bug: From Integer Range Inconsistency to Bound Check Elimination then RCE
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RISK
open ↗GitHub PoC★ 1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open ↗Exploit-DB
SolarWinds Platform 2024.1 SR1 - Race Condition
SolarWinds Platform Race Condition Vulnerability
38RISK
open ↗GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗VulnCheck XDB
remote-with-credentials
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISK
open ↗GitHub PoC
zerobytesecure/CVE-2019-19781
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗VulnCheck XDB
initial-access
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗Metasploit300
Fortra FileCatalyst Workflow SQL Injection (CVE-2024-5276)
SQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
65RISK
open ↗Metasploit300
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
MOVEit Transfer Authentication Bypass Vulnerability
85RISK
open ↗GitHub PoC
CVE-2024-6028 Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISK
open ↗GitHub PoC
CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗GitHub PoC★ 1
Proof of concept of CVE-2024-29868 affecting Apache StreamPipes from 0.69.0 through 0.93.0
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.