Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
77,231 exploits
GitHub PoC★ 2
PoC for the Untrusted Pointer Dereference in the appid.sys driver
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open ↗GitHub PoC★ 1
FoxyProxys/CVE-2024-27956
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC
Turvanõrkuse CVE 2024 3273 analüüs: D-Link seadmete käsusüst
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open ↗GitHub PoC
Vignesh2712/Automation-for-Juniper-cve-2023-36845
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open ↗GitHub PoC★ 1
Joomla! v4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 1
Jenkins CVE-2024-23897: Arbitrary File Read Vulnerability
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗GitHub PoC★ 2
CVE-2024-21413 Microsoft Outlook RCE Exploit
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Bypass for CVE-2007-4559 Trellix patch
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RISK
open ↗GitHub PoC
CVE-2024-27956 WORDPRESS RCE PLUGIN
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC★ 7
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open ↗GitHub PoC★ 7
Exploit for Microsoft SmartScreen malicious execution (april 2024)
SmartScreen Prompt Security Feature Bypass Vulnerability
83RISK
open ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open ↗VulnCheck XDB
initial-access
WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.10 - Local File Inclusion vulnerability
41RISK
open ↗VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC
xsxtw/CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open ↗GitHub PoC
xsxtw/CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC
ShellUnease/CVE-2024-34833-payroll-management-system-rce
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settin
48RISK
open ↗GitHub PoC
xsxtw/CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC
xsxtw/SpringFramework_CVE-2022-22965_RCE
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC★ 90
PoC for SQL Injection in CVE-2024-27956
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC★ 4
jakabakos/CVE-2024-4040-CrushFTP-File-Read-vulnerability
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open ↗GitHub PoC
Neo-XeD/CVE-2024-33775
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a cr
48RISK
open ↗GitHub PoC
tronghoang89/cve-2019-16113
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open ↗GitHub PoC
PoC for CVE-2023-32749 affecting Pydio Cells
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RISK
open ↗VulnCheck XDB
infoleak
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.