Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
77,231 exploits
VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC
W3BW/CVE-2024-27956-RCE-File-Package
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open ↗VulnCheck XDB
initial-access
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open ↗GitHub PoC★ 4
High CVE-2024-4761 Exploit
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds
76RISK
open ↗VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC★ 2
Checker for CVE-2021-3156 with static version check
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗GitHub PoC★ 15
aelmokhtar/CVE-2024-34716
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISK
open ↗GitHub PoC★ 5
jakabakos/CVE-2023-26360-adobe-coldfusion-rce-exploit
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open ↗GitHub PoC
CVE-2024-34832
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a craf
48RISK
open ↗GitHub PoC★ 1
Updated python3 exploit for CVE-2018-10583 (LibreOffice/Open Office - '.odt' Information Disclosure )
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISK
open ↗GitHub PoC
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open ↗VulnCheck XDB
client-side
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISK
open ↗Exploit-DB
Apache mod_proxy_cluster 1.2.6 - Stored XSS
Mod_cluster/mod_proxy_cluster: stored cross site scripting
33RISK
open ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open ↗GitHub PoC★ 2
POC for CVE-2024-4701
Path Traversal vulnerability via File Uploads in Genie
53RISK
open ↗VulnCheck XDB
infoleak
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open ↗GitHub PoC
andrelia-hacks/CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open ↗GitHub PoC★ 7
Kernel Exploit for CVE-2016-6187 (Local Privilege Escalation)
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RISK
open ↗VulnCheck XDB
initial-access
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open ↗VulnCheck XDB
client-side
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISK
open ↗VulnCheck XDB
infoleak
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗VulnCheck XDB
infoleak
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗GitHub PoC★ 2
Apache Superset - Authentication Bypass
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗GitHub PoC★ 1
Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass)
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open ↗VulnCheck XDB
infoleak
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open ↗GitHub PoC
th3Hellion/CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.