Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
initial-access
CVE-2021-2564604 Oct 2024
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-0297CRITICAL04 Oct 2024
Code Injection in pyload/pyload
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware04 Oct 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack04 Oct 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM03 Oct 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
local
CVE-2024-0582HIGH03 Oct 2024
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open
VulnCheck XDB
initial-access
CVE-2024-8353CRITICAL30 Sep 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack30 Sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware30 Sep 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware29 Sep 2024
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware29 Sep 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-43917CRITICAL29 Sep 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-29269HIGH28 Sep 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open
VulnCheck XDB
infoleak
CVE-2024-38816HIGH28 Sep 2024
CVE-2024-38816: Path traversal vulnerability in functional web frameworks
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack28 Sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM28 Sep 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALunder attack28 Sep 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware27 Sep 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-9014CRITICAL26 Sep 2024
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISK
open
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM25 Sep 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-7593CRITICALunder attack24 Sep 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALunder attack24 Sep 2024
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL23 Sep 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-3273HIGHunder attack21 Sep 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL20 Sep 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack20 Sep 2024
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMunder attack20 Sep 2024
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware20 Sep 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-8522CRITICAL19 Sep 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RISK
open
VulnCheck XDB
infoleak
CVE-2023-1177CRITICAL19 Sep 2024
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
previouspage 111 / 273next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.