Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,864cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL20 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware20 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware19 Nov 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
local
CVE-2024-49039HIGHunder attackransomware19 Nov 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3722HIGH19 Nov 2024
Avaya Aura Device Services Remote Code Execution
56RISK
open
VulnCheck XDB
infoleak
CVE-2018-376019 Nov 2024
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware19 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware19 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL18 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-3806CRITICAL18 Nov 2024
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-9593HIGH18 Nov 2024
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RISK
open
VulnCheck XDB
infoleak
CVE-2024-1698CRITICAL16 Nov 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-8856CRITICAL16 Nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL16 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL15 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-3495CRITICAL15 Nov 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-52301HIGH15 Nov 2024
Laravel allows environment manipulation via query string
53RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL15 Nov 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALunder attack15 Nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL15 Nov 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2019-1653HIGHunder attack14 Nov 2024
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27997CRITICALunder attackransomware14 Nov 2024
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM14 Nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-8963CRITICALunder attack13 Nov 2024
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-8069MEDIUMunder attack13 Nov 2024
Limited remote code execution with privilege of a NetworkService Account access
68RISK
open
previouspage 106 / 272next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.