Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,939cataloged exploits
32,191CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALunder attack22 Apr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack22 Apr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware21 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware21 Apr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-32238CRITICAL20 Apr 2024
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL20 Apr 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack19 Apr 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0305MEDIUM18 Apr 2024
Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware17 Apr 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware17 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2023-25194HIGH17 Apr 2024
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-5016416 Apr 2024
Apache Struts: File upload component had a directory traversal vulnerability
45RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware16 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMunder attack15 Apr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-23897CRITICALunder attackransomware15 Apr 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack15 Apr 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack14 Apr 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-28432HIGHunder attack13 Apr 2024
Minio Information Disclosure in Cluster Deployment
100RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware13 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2024-28255CRITICAL12 Apr 2024
Authentication Bypass in OpenMetadata
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-29269HIGH12 Apr 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open
previouspage 129 / 273next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.