Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
24,459 exploits
Exploit-DB
JUX Real Estate 3.4.0 - SQL Injection
CVE-2025-2126MEDIUMwebappsphp20 Mar 2025
JoomlaUX JUX Real Estate GET Parameter realties sql injection
38RISK
open
Exploit-DB
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
CVE-2023-0159webappsphp19 Mar 2025
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
Exploit-DB
Chamilo LMS 1.11.24 - Remote Code Execution (RCE)
CVE-2023-4220HIGHwebappsphp18 Mar 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
Exploit-DB
openSIS 9.1 - SQLi (Authenticated)
CVE-2024-46626HIGHwebappsphp01 Oct 2024
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
41RISK
open
Exploit-DB
Devika v1 - Path Traversal via 'snapshot_path'
CVE-2024-40422CRITICALwebappspython04 Aug 2024
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISK
open
Exploit-DB
SolarWinds Platform 2024.1 SR1 - Race Condition
CVE-2024-28999MEDIUMwebappsmultiple26 Jun 2024
SolarWinds Platform Race Condition Vulnerability
38RISK
open
Exploit-DB
Rocket LMS 1.9 - Persistent Cross Site Scripting (XSS)
CVE-2024-34241MEDIUMwebappsphp19 May 2024
A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa
33RISK
open
Exploit-DB
htmlLawed 1.2.5 - Remote Code Execution (RCE)
CVE-2022-35914CRITICALunder attackwebappsphp19 May 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
Exploit-DB
Wordpress Theme XStore 9.3.8 - SQLi
CVE-2024-33559CRITICALwebappsphp19 May 2024
WordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
48RISK
open
Exploit-DB
Apache OFBiz 18.12.12 - Directory Traversal
CVE-2024-32113CRITICALunder attackwebappsjava19 May 2024
Apache OFBiz: Path traversal leading to RCE
100RISK
open
Exploit-DB
Apache mod_proxy_cluster 1.2.6 - Stored XSS
CVE-2023-6710MEDIUMwebappsphp13 May 2024
Mod_cluster/mod_proxy_cluster: stored cross site scripting
33RISK
open
Exploit-DB
Laravel Framework 11 - Credential Leakage
CVE-2024-29291webappsphp21 Apr 2024
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/log
23RISK
open
Exploit-DB
Palo Alto PAN-OS < v11.1.2-h3 - Command Injection and Arbitrary File Creation
CVE-2024-3400CRITICALunder attackransomwareremotelinux_x86-6421 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
Exploit-DB
OpenClinic GA 5.247.01 - Path Traversal (Authenticated)
CVE-2023-40279HIGHwebappsphp15 Apr 2024
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page param
41RISK
open
Exploit-DB
OpenClinic GA 5.247.01 - Information Disclosure
CVE-2023-40278HIGHwebappsphp15 Apr 2024
An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the pr
41RISK
open
Exploit-DB
Jenkins 2.441 - Local File Inclusion
CVE-2024-23897CRITICALunder attackransomwarewebappsjava15 Apr 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
Exploit-DB
djangorestframework-simplejwt 5.3.1 - Information Disclosure
CVE-2024-22513MEDIUMwebappspython15 Apr 2024
djangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web ap
33RISK
open
Exploit-DB
Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
CVE-2023-6019CRITICALwebappspython12 Apr 2024
Ray Command Injection in cpu_profile Parameter
85RISK
open
Exploit-DB
MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
CVE-2024-24747HIGHremotego12 Apr 2024
MinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
53RISK
open
Exploit-DB
GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
CVE-2024-31777CRITICALwebappsphp12 Apr 2024
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RISK
open
Exploit-DB
Gibbon LMS v26.0.00 - SSTI vulnerability
CVE-2024-24724CRITICALwebappsphp02 Apr 2024
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RISK
open
Exploit-DB
Casdoor < v1.331.0 - '/api/set-password' CSRF
CVE-2023-34927webappsgo02 Apr 2024
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISK
open
Exploit-DB
Axigen < 10.5.7 - Persistent Cross-Site Scripting
CVE-2023-48974CRITICALwebappsphp02 Apr 2024
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges
48RISK
open
Exploit-DB
Employee Management System 1.0 - _txtfullname_ and _txtphone_ SQL Injection
CVE-2024-24499webappsphp02 Apr 2024
20RISK
open
Exploit-DB
Microsoft Windows 10.0.17763.5458 - Kernel Privilege Escalation
CVE-2024-21338HIGHunder attackransomwarelocalwindows02 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
Exploit-DB
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
CVE-2024-24494MEDIUMwebappsphp02 Apr 2024
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via t
38RISK
open
Exploit-DB
Daily Habit Tracker 1.0 - SQL Injection
CVE-2024-24495CRITICALwebappsphp02 Apr 2024
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit
48RISK
open
Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
CVE-2024-24497webappsphp02 Apr 2024
20RISK
open
Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
CVE-2024-27356HIGHremotehardware02 Apr 2024
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RISK
open
Exploit-DB
Daily Habit Tracker 1.0 - Broken Access Control
CVE-2024-24496CRITICALwebappsphp02 Apr 2024
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,
53RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.