Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
77,302 exploits
VulnCheck XDB
initial-access
CVE-2023-4450MEDIUM07 Feb 2024
jeecgboot JimuReport Template injection
53RISK
open
VulnCheck XDB
initial-access
CVE-2023-6895MEDIUM07 Feb 2024
Hikvision Intercom Broadcasting System ping.php os command injection
70RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware07 Feb 2024
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
一款Spring综合漏洞的利用工具,工具目前支持Spring Cloud Gateway RCE(CVE-2022-22947)、Spring Framework RCE (CVE-2022-22965) 的检测以及利用
CVE-2022-22947CRITICALunder attack07 Feb 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware07 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC3
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
CVE-2024-23897CRITICALunder attackransomware07 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC61
CVE-2024-20931, this is the bypass of the patch of CVE-2023-21839
CVE-2023-21839HIGHunder attack06 Feb 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-6875CRITICAL05 Feb 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISK
open
GitHub PoC
trustcves/CVE-2024-24398
CVE-2024-24398CRITICAL05 Feb 2024
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker
48RISK
open
VulnCheck XDB
initial-access
CVE-2022-1040CRITICALunder attack05 Feb 2024
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC1
CVE-2023-6875 exploit written for Xakep.Ru
CVE-2023-6875CRITICAL05 Feb 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH05 Feb 2024
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
GitHub PoC
letsr00t/-2021-LOCALROOT-CVE-2021-22555
CVE-2021-22555HIGHunder attack05 Feb 2024
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC
xMr110/CVE-2022-1040
CVE-2022-1040CRITICALunder attack05 Feb 2024
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack04 Feb 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
xMr110/CVE-2020-14882
CVE-2020-14882CRITICALunder attack04 Feb 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
wechicken456/CVE-2021-4034-CTF-writeup
CVE-2021-4034HIGHunder attackransomware04 Feb 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
WLXQqwer/Jenkins-CVE-2024-23897-
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC22
Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC1
GoAnywhere MFT
CVE-2024-0204CRITICAL04 Feb 2024
Authentication Bypass in GoAnywhere MFT
85RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack04 Feb 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0204CRITICAL04 Feb 2024
Authentication Bypass in GoAnywhere MFT
85RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack04 Feb 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
VulnCheck XDB
local
CVE-2023-32233HIGH04 Feb 2024
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RISK
open
GitHub PoC
Shellshock exploit (CVE-2014-6271)
CVE-2014-6271CRITICALunder attack04 Feb 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
Triggering the famous libweb 0day vuln with libfuzzer
CVE-2023-4863HIGHunder attack04 Feb 2024
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC
semcms存在SQL注入(CVE-2024-25422 )
CVE-2024-25422CRITICAL04 Feb 2024
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC5
Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite
CVE-2019-2215HIGHunder attack04 Feb 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
previouspage 427 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.