Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
initial-access
CVE-2023-4220HIGH10 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH09 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
local
CVE-2024-38193HIGHunder attack09 Jul 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH09 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH08 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-4885CRITICALunder attack08 Jul 2024
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALunder attack07 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware06 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack06 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2024
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALunder attack05 Jul 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27532HIGHunder attackransomware05 Jul 2024
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISK
open
VulnCheck XDB
local
CVE-2024-30088HIGHunder attackransomware05 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack05 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack05 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware05 Jul 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack04 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-29552HIGHunder attack04 Jul 2024
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services.
83RISK
open
VulnCheck XDB
local
CVE-2024-1086HIGHunder attackransomware04 Jul 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack04 Jul 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack04 Jul 2024
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware04 Jul 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
previouspage 118 / 273next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.