Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
77,302 exploits
GitHub PoC29
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
CVE-2023-43208CRITICALunder attackransomware15 Mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware15 Mar 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
exploit for f5-big-ip RCE cve-2023-46747
CVE-2023-46747CRITICALunder attackransomware15 Mar 2024
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
CVE-2024-25004HIGHlocalwindows14 Mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf
41RISK
open
Exploit-DB
KiTTY 0.76.1.13 - Command Injection
CVE-2024-23749HIGHlocalwindows14 Mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic
41RISK
open
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5702MEDIUMremotehardware14 Mar 2024
Viessmann Vitogate 300 direct request
38RISK
open
Exploit-DB
Viessmann Vitogate 300 2.1.3.0 - Remote Code Execution (RCE)
CVE-2023-5222MEDIUMremotehardware14 Mar 2024
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
70RISK
open
Exploit-DB
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)
CVE-2023-42793CRITICALunder attackransomwareremotejava14 Mar 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
Exploit-DB
KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
CVE-2024-25003HIGHlocalwindows14 Mar 2024
KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf
41RISK
open
Exploit-DB
GitLab CE/EE < 16.7.2 - Password Reset
CVE-2023-7028CRITICALunder attackremotejava14 Mar 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
Exploit-DB
SolarView Compact 6.00 - Command Injection
CVE-2023-23333CRITICALremotehardware14 Mar 2024
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RISK
open
GitHub PoC
manrop2702/CVE-2020-7961
CVE-2020-7961CRITICALunder attack14 Mar 2024
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
Metasploit600
Ghostscript Command Execution via Format String
CVE-2024-29510MEDIUM14 Mar 2024
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with
33RISK
open
GitHub PoC
A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.
CVE-2023-20048CRITICAL14 Mar 2024
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
53RISK
open
Exploit-DB
Honeywell PM43 < P10.19.050004 - Remote Code Execution (RCE)
CVE-2023-3710CRITICALremotehardware14 Mar 2024
Printer web page invalid command execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALunder attack14 Mar 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC150
out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability
CVE-2024-21762CRITICALunder attackransomware13 Mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
GitHub PoC16
Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)
CVE-2024-21762CRITICALunder attackransomware13 Mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-21762CRITICALunder attackransomware13 Mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2024-21762CRITICALunder attackransomware13 Mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
Metasploit600
WordPress wp-automatic Plugin SQLi Admin Creation
CVE-2024-27956CRITICAL13 Mar 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC
corelight/CVE-2021-38647-noimages
CVE-2021-38647CRITICALunder attackransomware13 Mar 2024
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
100RISK
open
Metasploit600
NorthStar C2 XSS to Agent RCE
CVE-2024-28741HIGH12 Mar 2024
Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code
58RISK
open
GitHub PoC1
CVE-2023-23752 Data Extractor
CVE-2023-23752MEDIUMunder attack12 Mar 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC42
Proof-of-concept exploit for CVE-2024-25153.
CVE-2024-25153CRITICAL12 Mar 2024
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
60RISK
open
GitHub PoC3
hienkiet/CVE-2022-21445-for-12.2.1.3.0-Weblogic
CVE-2022-21445CRITICALunder attack12 Mar 2024
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
90RISK
open
Metasploit300
CVE-2024-20767 - Adobe Coldfusion Arbitrary File Read
CVE-2024-20767HIGHunder attack12 Mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware12 Mar 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-21445CRITICALunder attack12 Mar 2024
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
90RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack12 Mar 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
previouspage 419 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.