Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,231 exploits
GitHub PoC
10cks/CVE-2024-32002-submod
CVE-2024-32002CRITICAL19 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
10cks/CVE-2024-32002-smash
CVE-2024-32002CRITICAL19 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
aitorcastel/poc_CVE-2024-32002_submodule
CVE-2024-32002CRITICAL19 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
10cks/CVE-2024-32002-hulk
CVE-2024-32002CRITICAL19 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
aitorcastel/poc_CVE-2024-32002
CVE-2024-32002CRITICAL19 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
10cks/CVE-2024-32002-POC
CVE-2024-32002CRITICAL19 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
Exploit-DB
Apache OFBiz 18.12.12 - Directory Traversal
CVE-2024-32113CRITICALunder attackwebappsjava19 May 2024
Apache OFBiz: Path traversal leading to RCE
100RISK
open
Exploit-DB
htmlLawed 1.2.5 - Remote Code Execution (RCE)
CVE-2022-35914CRITICALunder attackwebappsphp19 May 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
GitHub PoC
CVE-2021-22205 exploit script
CVE-2021-22205CRITICALunder attackransomware19 May 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
Exploit-DB
Wordpress Theme XStore 9.3.8 - SQLi
CVE-2024-33559CRITICALwebappsphp19 May 2024
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-29269HIGH19 May 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open
GitHub PoC
A exploit script for CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware19 May 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware19 May 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC1
Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal
CVE-2020-3187CRITICAL19 May 2024
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISK
open
GitHub PoC
X-Projetion/Exploiting-PwnKit-CVE-2021-4034-
CVE-2021-4034HIGHunder attack19 May 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALunder attackransomware19 May 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack19 May 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery
CVE-2021-40438CRITICALunder attackransomware19 May 2024
mod_proxy SSRF
100RISK
open
GitHub PoC1
WHOISshuvam/CVE-2015-1397
CVE-2015-139718 May 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2015-139718 May 2024
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RISK
open
GitHub PoC3
A PoC exploit for CVE-2014-6271 - Shellshock
CVE-2014-6271CRITICALunder attack18 May 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack18 May 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC7
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
CVE-2024-21338HIGHunder attackransomware18 May 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2023-4596CRITICAL18 May 2024
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-27972CRITICAL18 May 2024
WordPress WP Fusion Lite plugin <= 3.41.24 - Remote Code Execution (RCE) vulnerability
48RISK
open
GitHub PoC1
jakob-pennington/cve-2024-32002-poc-rce
CVE-2024-32002CRITICAL18 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC9
local poc for CVE-2024-32002
CVE-2024-32002CRITICAL18 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC109
CVE-2024-32002 RCE PoC
CVE-2024-32002CRITICAL18 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
CVE-2023-4596 Vulnerable Exploit and Checker Version
CVE-2023-4596CRITICAL18 May 2024
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC
jakob-pennington/cve-2024-32002-submodule-rce
CVE-2024-32002CRITICAL18 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
previouspage 400 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.