Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL01 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware30 Apr 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALunder attack30 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
local
CVE-2024-1086HIGHunder attackransomware30 Apr 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware30 Apr 2024
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware30 Apr 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack29 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-2667CRITICAL28 Apr 2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
63RISK
open
VulnCheck XDB
client-side
CVE-2021-4206328 Apr 2024
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage
43RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack28 Apr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL27 Apr 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware27 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-22515CRITICALunder attackransomware26 Apr 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
client-side
CVE-2018-20250HIGHunder attackransomware26 Apr 2024
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware25 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL25 Apr 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack25 Apr 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware24 Apr 2024
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware24 Apr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALunder attack24 Apr 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack23 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3273HIGHunder attack23 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware23 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack22 Apr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALunder attack22 Apr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-0482CRITICAL22 Apr 2024
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware22 Apr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
previouspage 128 / 273next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.