Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,231 exploits
Metasploit600
Atlassian Confluence Administrator Code Macro Remote Code Execution
CVE-2024-21683HIGH21 May 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISK
open
GitHub PoC
Este script está creado para mostar usuarios de DVR, VULNERABILIDAD (CVE-2018-9995)
CVE-2018-999521 May 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-999521 May 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC1
Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.
CVE-2024-4323CRITICAL21 May 2024
Fluent Bit Memory Corruption Vulnerability
53RISK
open
GitHub PoC3
Patch your D-Link device affected by CVE-2024-3272
CVE-2024-3272CRITICALunder attack21 May 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
100RISK
open
GitHub PoC6
Este script demuestra cómo explotar la vulnerabilidad CVE-2024-32002 para obtener una reverse shell, proporcionando acceso remoto al sistema afectado. Úselo con precaución en entornos controlados y solo con fines educativos o de pruebas de seguridad.
CVE-2024-32002CRITICAL21 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
This script checks if a target host is vulnerable to CVE-2023-34992 by sending a crafted payload to the FortiSIEM appliance. It then analyzes the response to determine if the host is vulnerable.
CVE-2023-34992CRITICAL21 May 2024
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISK
open
GitHub PoC
CVE-2024-32002 POC
CVE-2024-32002CRITICAL21 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Securenetology/CVE-2013-3900
CVE-2013-3900MEDIUMunder attack21 May 2024
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC
CVE-2024-32002 hook POC
CVE-2024-32002CRITICAL21 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
local
CVE-2023-2640HIGH21 May 2024
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISK
open
GitHub PoC57
CVE-2024-4367 arbitrary js execution in pdf js
CVE-2024-4367MEDIUM20 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC3
jweny/CVE-2024-32002_HOOK
CVE-2024-32002CRITICAL20 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC1
CVE-2024-32002-hook
CVE-2024-32002CRITICAL20 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC140
Time Based SQL Injection in Zabbix Server Audit Log --> RCE
CVE-2024-22120CRITICAL20 May 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISK
open
GitHub PoC1
CrackerCat/CVE-2024-32002_EXP
CVE-2024-32002CRITICAL20 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC11
Unlock your Huawei device with ADB (CVE-2019-2215)
CVE-2019-2215HIGHunder attack20 May 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC3
jweny/CVE-2024-32002_EXP
CVE-2024-32002CRITICAL20 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC203
CVE-2024-4367 & CVE-2024-34342 Proof of Concept
CVE-2024-4367MEDIUM20 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC15
This proof-of-concept script demonstrates how to exploit CVE-2024-4323, a memory corruption vulnerability in Fluent Bit, enabling remote code execution.
CVE-2024-4323CRITICAL20 May 2024
Fluent Bit Memory Corruption Vulnerability
53RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack20 May 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
VulnCheck XDB
initial-access
CVE-2024-23108CRITICAL20 May 2024
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISK
open
GitHub PoC
fabdotnet/CVE-2023-27100
CVE-2023-27100CRITICAL20 May 2024
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-22120CRITICAL20 May 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware19 May 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-29269HIGH19 May 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware19 May 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
GitHub PoC
10cks/CVE-2024-32002-submod
CVE-2024-32002CRITICAL19 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
10cks/CVE-2024-32002-linux-submod
CVE-2024-32002CRITICAL19 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
Exploit-DB
Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
CVE-2024-34241MEDIUMwebappsphp19 May 2024
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa
33RISK
open
previouspage 399 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.