Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
77,302 exploits
GitHub PoC23
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
CVE-2024-21887CRITICALunder attackransomware16 Jan 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46805HIGHunder attackransomware16 Jan 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-21887CRITICALunder attackransomware16 Jan 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISK
open
GitHub PoC
Pol-Ruiz/CVE-2021-4034
CVE-2021-4034HIGHunder attackransomware16 Jan 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC26
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server PoC
CVE-2023-22527CRITICALunder attackransomware16 Jan 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
Metasploit600
Atlassian Confluence SSTI Injection
CVE-2023-22527CRITICALunder attackransomware16 Jan 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
GitHub PoC5
Simple scanner for scanning a list of ip-addresses for vulnerable Ivanti Pulse Secure devices
CVE-2023-46805HIGHunder attackransomware16 Jan 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-4437CRITICALunder attack15 Jan 2024
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
GitHub PoC5
CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware15 Jan 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
1.验证CVE-2016-4437、2.解析rememberMe的文件和CBC加密的IV偏移
CVE-2016-4437CRITICALunder attack15 Jan 2024
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3581315 Jan 2024
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware15 Jan 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware15 Jan 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC7
POC Checker for ivanti CVE-2024-21887 Command injcetion
CVE-2024-21887CRITICALunder attackransomware14 Jan 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-46805HIGHunder attackransomware14 Jan 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISK
open
GitHub PoC10
Scanner for CVE-2023-46805 - Ivanti Connect Secure
CVE-2023-46805HIGHunder attackransomware14 Jan 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-21887CRITICALunder attackransomware14 Jan 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISK
open
GitHub PoC
Program ini adalah alat (tool) yang dibuat untuk memeriksa keamanan sistem Minio terkait dengan kerentanan CVE-2022-35919
CVE-2022-35919HIGH13 Jan 2024
Authenticated requests for server update admin API allows path traversal in minio
53RISK
open
VulnCheck XDB
initial-access
CVE-2023-5146713 Jan 2024
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-6875CRITICAL13 Jan 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-065612 Jan 2024
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of S
35RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack12 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack12 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack12 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack12 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
Metasploit300
GitLab Password Reset Account Takeover
CVE-2023-7028CRITICALunder attack11 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
Metasploit600
Netis router MW5360 unauthenticated RCE.
CVE-2024-22729CRITICAL11 Jan 2024
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter
65RISK
open
VulnCheck XDB
initial-access
CVE-2023-4907011 Jan 2024
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RISK
open
VulnCheck XDB
infoleak
CVE-2023-28432HIGHunder attack11 Jan 2024
Minio Information Disclosure in Cluster Deployment
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-6567CRITICAL11 Jan 2024
LearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
75RISK
open
previouspage 434 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.