Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,231 exploits
GitHub PoC
part of poc cve-2024-32002
CVE-2024-32002CRITICAL24 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
Metasploit300
Ivanti EPM RecordGoodApp SQLi RCE
CVE-2024-29824CRITICALunder attack24 May 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISK
open
GitHub PoC2
Unauthenticated Path Traversal in Nexus Repository 3
CVE-2024-4956HIGH24 May 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC3
Unauthenticated Path Traversal in Nexus Repository 3
CVE-2024-4956HIGH23 May 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC1
CVE-2024-4367 mitigation for Odoo 14.0
CVE-2024-4367MEDIUM23 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC1
Nexus Repository Manager 3 Unauthenticated Path Traversal
CVE-2024-4956HIGH23 May 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC3
CVE-2024-4956 Nuclei Template
CVE-2024-4956HIGH23 May 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC4
POC for ImageMagick 6.9.6-4. This is a POC which was inspired by fullwaywang discovery of CVE-2023-34152.
CVE-2023-34152CRITICAL23 May 2024
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
48RISK
open
Metasploit600
WordPress Hash Form Plugin RCE
CVE-2024-5084CRITICAL23 May 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
GitHub PoC
PoC Exploit for CVE-2024-32002
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
infoleak
CVE-2024-3495CRITICAL23 May 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-21683HIGH23 May 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISK
open
GitHub PoC8
CVE-2024-3495 Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
CVE-2024-3495CRITICAL23 May 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISK
open
GitHub PoC1
poc of git rce using cve-2024-32002
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
PoC Exploit for CVE-2024-32002
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC2
10cks/CVE-2024-32002-EXP
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Repo for testing CVE-2024-32002
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC4
The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based clients and servers using a version of FreeRDP prior to version 3.5.0 or 2.11.6 are vulnerable to out-of-bounds reading12. Versions 3.5.0 and 2.11.6 correct the problem
CVE-2024-32459CRITICAL22 May 2024
FreeRDP Out-Of-Bounds Read in ncrush_decompress
48RISK
open
GitHub PoC
yuansec/CVE-2024-4323-dos_poc
CVE-2024-4323CRITICAL22 May 2024
Fluent Bit Memory Corruption Vulnerability
53RISK
open
GitHub PoC
This is the main repository for CVE 2024-32002, and requires recursive cloning because it contains the submodels necessary for execution.
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
CVE-2024-32002-hook
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC2
bfengj/CVE-2024-32002-Exploit
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
bfengj/CVE-2024-32002-hook
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
1mxml/CVE-2024-32002-poc
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Proof Of Concept for the CVE-2016-10033 (PHPMailer)
CVE-2016-10033CRITICALunder attack22 May 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC
Presentazione per il corsi di sicurezza Informatica sulla vulnerabilità CVE-2024-3094
CVE-2024-3094CRITICAL22 May 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC4
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
CVE-2024-4367MEDIUM22 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC11
YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js
CVE-2024-4367MEDIUM22 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
CVE-2024-32002 hook POC
CVE-2024-32002CRITICAL21 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
Metasploit600
Atlassian Confluence Administrator Code Macro Remote Code Execution
CVE-2024-21683HIGH21 May 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISK
open
previouspage 398 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.