Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,231 exploits
VulnCheck XDB
initial-access
CVE-2024-29895CRITICAL15 May 2024
Cacti command injection in cmd_realtime.php
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL15 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC
W3BW/CVE-2024-27956-RCE-File-Package
CVE-2024-27956CRITICAL15 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH15 May 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-26360HIGHunder attack14 May 2024
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
GitHub PoC4
High CVE-2024-4761 Exploit
CVE-2024-4761HIGHunder attack14 May 2024
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL14 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC2
Checker for CVE-2021-3156 with static version check
CVE-2021-3156HIGHunder attack14 May 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC15
aelmokhtar/CVE-2024-34716
CVE-2024-34716CRITICAL14 May 2024
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISK
open
GitHub PoC5
jakabakos/CVE-2023-26360-adobe-coldfusion-rce-exploit
CVE-2023-26360HIGHunder attack14 May 2024
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
GitHub PoC
CVE-2024-34832
CVE-2024-34832CRITICAL14 May 2024
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a craf
48RISK
open
GitHub PoC1
Updated python3 exploit for CVE-2018-10583 (LibreOffice/Open Office - '.odt' Information Disclosure )
CVE-2018-1058313 May 2024
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RISK
open
GitHub PoC
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
CVE-2024-4040CRITICALunder attack13 May 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
client-side
CVE-2023-40000HIGH13 May 2024
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISK
open
Exploit-DB
Apache mod_proxy_cluster 1.2.6 - Stored XSS
CVE-2023-6710MEDIUMwebappsphp13 May 2024
Mod_cluster/mod_proxy_cluster: stored cross site scripting
33RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack13 May 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC2
POC for CVE-2024-4701
CVE-2024-4701CRITICAL13 May 2024
Path Traversal vulnerability via File Uploads in Genie
53RISK
open
VulnCheck XDB
infoleak
CVE-2024-1561HIGH12 May 2024
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open
GitHub PoC
andrelia-hacks/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware12 May 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC7
Kernel Exploit for CVE-2016-6187 (Local Privilege Escalation)
CVE-2016-618712 May 2024
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RISK
open
Metasploit600
Cacti Import Packages RCE
CVE-2024-25641CRITICAL12 May 2024
Cacti RCE vulnerability when importing packages
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware12 May 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
client-side
CVE-2023-40000HIGH12 May 2024
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISK
open
VulnCheck XDB
infoleak
CVE-2023-27524HIGHunder attack11 May 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack11 May 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-27524HIGHunder attack11 May 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC2
Apache Superset - Authentication Bypass
CVE-2023-27524HIGHunder attack11 May 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC1
Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass)
CVE-2023-27524HIGHunder attack11 May 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-1561HIGH11 May 2024
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open
GitHub PoC
th3Hellion/CVE-2024-21413
CVE-2024-21413CRITICALunder attack11 May 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
previouspage 402 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.