Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,943cataloged exploits
32,194CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware06 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware06 Feb 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-20085HIGHunder attack06 Feb 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL05 Feb 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL05 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware05 Feb 2025
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH04 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware02 Feb 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-370402 Feb 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-26319CRITICAL02 Feb 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH02 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL02 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware02 Feb 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware02 Feb 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-023231 Jan 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware30 Jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-33891HIGHunder attack30 Jan 2025
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware30 Jan 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack30 Jan 2025
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHunder attack30 Jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-0235MEDIUM30 Jan 2025
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALunder attackransomware29 Jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALunder attackransomware29 Jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-11972CRITICAL29 Jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALunder attackransomware29 Jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALunder attackransomware29 Jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-48248HIGHunder attack28 Jan 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALunder attackransomware27 Jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-2961HIGH27 Jan 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL26 Jan 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.