Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware07 Jun 2024
Information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-14883HIGHunder attack07 Jun 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware07 Jun 2024
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware07 Jun 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1472MEDIUMunder attackransomware06 Jun 2024
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL06 Jun 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL06 Jun 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-5324HIGH06 Jun 2024
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
41RISK
open
VulnCheck XDB
initial-access
CVE-2018-133506 Jun 2024
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack06 Jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware06 Jun 2024
Information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-32640CRITICAL06 Jun 2024
MasaCMS SQL Injection vulnerability
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-4295CRITICAL05 Jun 2024
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-4358CRITICALunder attack05 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware05 Jun 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2024-2961HIGH04 Jun 2024
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-4358CRITICALunder attack04 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4358CRITICALunder attack04 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-21683HIGH04 Jun 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISK
open
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMunder attack04 Jun 2024
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware04 Jun 2024
Information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware03 Jun 2024
Information disclosure
100RISK
open
previouspage 123 / 273next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.