Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,299cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
77,231 exploits
Exploit-DB
Daily Habit Tracker 1.0 - SQL Injection
CVE-2024-24495CRITICALwebappsphp02 Apr 2024
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit
48RISK
open
Exploit-DB
Gibbon LMS v26.0.00 - SSTI vulnerability
CVE-2024-24724CRITICALwebappsphp02 Apr 2024
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RISK
open
Exploit-DB
Employee Management System 1.0 - _txtfullname_ and _txtphone_ SQL Injection
CVE-2024-24499webappsphp02 Apr 2024
20RISK
open
GitHub PoC3
apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC2
Detectar CVE-2024-3094
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
CVE-2024-3094 XZ Backdoor Detector
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC14
Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware02 Apr 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
CVE-2024-27356HIGHremotehardware02 Apr 2024
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RISK
open
GitHub PoC
Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.
CVE-2024-3094CRITICAL02 Apr 2024
Xz: malicious code in distributed source
70RISK
open
Exploit-DB
Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation
CVE-2024-21338HIGHunder attackransomwarelocalwindows02 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
Em fevereiro de 2024, foi identificado duas novas vulnerabilidades que afetam o servidor JetBrains TeamCity (CVE-2024-27198 e CVE-2024-27199)
CVE-2024-27198CRITICALunder attackransomware02 Apr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC
YangHyperData/LOGJ4_PocShell_CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware02 Apr 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
cjybao/CVE-2024-1709-and-CVE-2024-1708
CVE-2024-1709CRITICALunder attackransomware02 Apr 2024
Authentication bypass using an alternate path or channel
100RISK
open
Exploit-DB
Axigen < 10.5.7 - Persistent Cross-Site Scripting
CVE-2023-48974CRITICALwebappsphp02 Apr 2024
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges
48RISK
open
VulnCheck XDB
local
CVE-2023-32233HIGH01 Apr 2024
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RISK
open
GitHub PoC
This is my malware
CVE-2023-38831HIGHunder attackransomware01 Apr 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
CVE-2024-20767HIGHunder attack01 Apr 2024
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-20767HIGHunder attack01 Apr 2024
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
GitHub PoC4
Education purpose for CVE-2018-10933
CVE-2018-10933CRITICAL01 Apr 2024
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
Obsidian notes about CVE-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC3
Checker - CVE-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
dah4k/CVE-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC17
XZ Backdoor Extract(Test on Ubuntu 23.10)
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC3,555
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
mightysai1997/CVE-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
ackemed/detectar_cve-2024-3094
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC1
galacticquest/cve-2024-3094-detect
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
mightysai1997/CVE-2024-3094-info
CVE-2024-3094CRITICAL01 Apr 2024
Xz: malicious code in distributed source
70RISK
open
previouspage 413 / 2,575next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.