Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,226cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,151 exploits
GitHub PoC1
PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC2
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
CVE-2024-27956CRITICAL07 Jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC
CVE-2024-24919 exploit that checks more files for better visibility
CVE-2024-24919HIGHunder attackransomware07 Jun 2024
Information disclosure
100RISK
open
GitHub PoC
oracle weblogic
CVE-2020-14883HIGHunder attack07 Jun 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
princew88/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC43
POC & $BASH script for CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC317
PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC22
huseyinstif/CVE-2024-4577-Nuclei-Template
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
taida957789/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
Wh02m1/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
Nuclei Template for CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
CVE-2022-29464 exploit script
CVE-2022-29464CRITICALunder attackransomware07 Jun 2024
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC
graphite-org/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
WanLiChangChengWanLiChang/CVE-2024-4577-RCE-EXP
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
CVE-2021-22204 exploit script
CVE-2021-22204MEDIUMunder attack07 Jun 2024
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
Metasploit600
PHP CGI Argument Injection Remote Code Execution
CVE-2024-4577CRITICALunder attackransomware06 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC4
conan-sudo/CVE-2019-14974-bypass
CVE-2019-1497406 Jun 2024
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
43RISK
open
GitHub PoC
A script to exploit CVE-2020-1472 (Zerologon)
CVE-2020-1472MEDIUMunder attackransomware06 Jun 2024
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
sql延时注入poc
CVE-2024-32640CRITICAL06 Jun 2024
MasaCMS SQL Injection vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL06 Jun 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
DigitalNinja00/CVE-2018-1335
CVE-2018-133506 Jun 2024
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack06 Jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL06 Jun 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-5324HIGH06 Jun 2024
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
41RISK
open
GitHub PoC
WanLiChangChengWanLiChang/CVE-2024-25600
CVE-2024-25600CRITICAL06 Jun 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
muhammad1596/CVE-2022-0847-DirtyPipe-Exploits
CVE-2022-0847HIGHunder attack06 Jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
NanoWraith/CVE-2024-25600
CVE-2024-25600CRITICAL06 Jun 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
NanoWraith/CVE-2024-5084
CVE-2024-5084CRITICAL06 Jun 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
GitHub PoC
CVE-2024-4295 Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
CVE-2024-4295CRITICAL06 Jun 2024
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISK
open
previouspage 390 / 2,572next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.