Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
client-side
CVE-2023-40000HIGH13 May 2024
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack13 May 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware12 May 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-1561HIGH12 May 2024
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open
VulnCheck XDB
client-side
CVE-2023-40000HIGH12 May 2024
WordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
68RISK
open
VulnCheck XDB
infoleak
CVE-2023-27524HIGHunder attack11 May 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-27524HIGHunder attack11 May 2024
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-1561HIGH11 May 2024
Arbitrary Local File Read via Component Method Invocation in gradio-app/gradio
56RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack11 May 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack10 May 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-7169CRITICALunder attack10 May 2024
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-3806CRITICAL10 May 2024
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-3807HIGH10 May 2024
Porto <= 7.1.0 - Authenticated (Contributor+) Local File Inclusion via Post Meta
41RISK
open
VulnCheck XDB
infoleak
CVE-2018-999509 May 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware09 May 2024
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware09 May 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware08 May 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack08 May 2024
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware07 May 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-9670CRITICALunder attack05 May 2024
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack05 May 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack04 May 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-21413CRITICALunder attack03 May 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack03 May 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware03 May 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27971HIGH03 May 2024
WordPress Premmerce Permalink Manager for WooCommerce plugin <= 2.3.10 - Local File Inclusion vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL03 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL01 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack01 May 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack01 May 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
previouspage 127 / 273next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.