Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,934cataloged exploits
32,189CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack18 Feb 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
infoleak
CVE-2024-13159CRITICALunder attack18 Feb 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL17 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack17 Feb 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1881816 Feb 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-24016CRITICALunder attack16 Feb 2025
Remote code execution in Wazuh server
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack14 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware14 Feb 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL14 Feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware14 Feb 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
client-side
CVE-2024-42009CRITICALunder attack13 Feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL13 Feb 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack13 Feb 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALunder attack13 Feb 2025
Remote code execution in Wazuh server
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-0108HIGHunder attack13 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware12 Feb 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack12 Feb 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack12 Feb 2025
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH12 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL11 Feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-53704HIGHunder attackransomware11 Feb 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack11 Feb 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
client-side
CVE-2024-42009CRITICALunder attack11 Feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-3864610 Feb 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-27348CRITICALunder attack10 Feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-0847HIGHunder attack09 Feb 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack08 Feb 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-39713HIGH07 Feb 2025
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RISK
open
VulnCheck XDB
client-side
CVE-2022-30190HIGHunder attackransomware07 Feb 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.