Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
77,302 exploits
GitHub PoC92
Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)
CVE-2024-29059HIGHunder attack11 Mar 2024
.NET Framework Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-21762CRITICALunder attackransomware11 Mar 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
GitHub PoC
CSV Injection in Addactis IBNRS 3.10.3.107
CVE-2024-29375CRITICAL11 Mar 2024
CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a craf
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-29059HIGHunder attack11 Mar 2024
.NET Framework Information Disclosure Vulnerability
100RISK
open
Exploit-DB
DataCube3 v1.0 - Unrestricted file upload 'RCE'
CVE-2024-25830CRITICALwebappsphp10 Mar 2024
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una
53RISK
open
Exploit-DB
Ladder v0.0.21 - Server-side request forgery (SSRF)
CVE-2024-27620HIGHwebappsgo10 Mar 2024
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RISK
open
Exploit-DB
DataCube3 v1.0 - Unrestricted file upload 'RCE'
CVE-2024-25832HIGHwebappsphp10 Mar 2024
F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to
46RISK
open
Exploit-DB
Akaunting < 3.1.3 - RCE
CVE-2024-22836CRITICALwebappsphp10 Mar 2024
An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc
60RISK
open
Exploit-DB
Numbas < v7.3 - Remote Code Execution
CVE-2024-27612MEDIUMwebappsnodejs10 Mar 2024
Numbas editor before 7.3 mishandles editing of themes and extensions.
38RISK
open
GitHub PoC17
Demo showing Claude Opus does not find CVE-2023-0266
CVE-2023-0266HIGHunder attack10 Mar 2024
Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
71RISK
open
Exploit-DB
Hide My WP < 6.2.9 - Unauthenticated SQLi
CVE-2022-4681CRITICALwebappsphp10 Mar 2024
Hide My WP < 6.2.9 - Unauthenticated SQLi
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware09 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC1
CharonDefalt/CVE-2024-27198-RCE
CVE-2024-27198CRITICALunder attackransomware09 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware09 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC8
A PoC exploit for CVE-2024-27198 - JetBrains TeamCity Authentication Bypass
CVE-2024-27198CRITICALunder attackransomware09 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware08 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC2
https://github.com/Phamchie/CVE-2023-3047
CVE-2023-3047CRITICAL08 Mar 2024
SQLi in TMT's Lockcell
48RISK
open
GitHub PoC
Exploit for CVE-2024-22393 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.
CVE-2024-22393CRITICAL08 Mar 2024
Apache Answer: Pixel Flood Attack by uploading the large pixel file
48RISK
open
GitHub PoC3
passwa11/CVE-2024-27198-RCE
CVE-2024-27198CRITICALunder attackransomware08 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" issue.
CVE-2019-1722508 Mar 2024
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i
23RISK
open
VulnCheck XDB
infoleak
CVE-2022-138607 Mar 2024
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RISK
open
GitHub PoC39
hd3s5aa/CVE-2023-21674
CVE-2023-21674HIGHunder attack07 Mar 2024
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC4
Phamchie/CVE-2023-3047
CVE-2023-3047CRITICAL07 Mar 2024
SQLi in TMT's Lockcell
48RISK
open
VulnCheck XDB
local
CVE-2023-21674HIGHunder attack07 Mar 2024
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
A PoC for CVE-2024-27198 written in Go
CVE-2024-27198CRITICALunder attackransomware07 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack07 Mar 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC3
Brute Hikvision CAMS with CVE-2021-36260 Exploit
CVE-2021-36260CRITICALunder attack07 Mar 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware07 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware06 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC157
CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4
CVE-2024-27198CRITICALunder attackransomware06 Mar 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
previouspage 420 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.