Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
13,352 exploits
GitHub PoC★ 1
The EXP/POC of CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open ↗GitHub PoC
t0mmy4/CVE-2019-12725-modified-exp
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RISK
open ↗GitHub PoC★ 14
A short scraper looking for a POC of CVE-2024-49112
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
Rahul-Thakur7/CVE-2023-21554
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open ↗GitHub PoC★ 21
LLfam/CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open ↗GitHub PoC
redspy-sec/CVE-2021-41773
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection
WordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
48RISK
open ↗GitHub PoC★ 3
Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised users.
Grafana path traversal
100RISK
open ↗GitHub PoC
tlavi00/CVE-2018-7750
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RISK
open ↗GitHub PoC★ 96
A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises from flaws in the file upload logic, which can be exploited to perform path traversal and malicious file uploads.
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open ↗GitHub PoC
CVE to CTF FP
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open ↗GitHub PoC★ 4
666asd/CVE-2024-23653
BuildKit interactive containers API does not validate entitlements check
48RISK
open ↗GitHub PoC
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RISK
open ↗GitHub PoC
Improved version of PikaChu CVE
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open ↗GitHub PoC★ 8
CVE-2024-55875 | GHSA-7mj5-hjjj-8rgw | http4k first CVE
http4k has a potential XXE (XML External Entity Injection) vulnerability
48RISK
open ↗GitHub PoC★ 13
CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system.
Arbitrary file read via symlinks in Ghost
45RISK
open ↗GitHub PoC
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
60RISK
open ↗GitHub PoC★ 9
s2-067(CVE-2024-53677)
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open ↗GitHub PoC★ 4
exploit CVE-2024-38475(mod_rewrite weakness with filesystem path matching)
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open ↗GitHub PoC
This repo contains both the exploit and the explaination of how this vulnerability is exploited
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open ↗GitHub PoC★ 25
Cleo Unrestricted file upload and download PoC (CVE-2024-50623)
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISK
open ↗GitHub PoC★ 8
This PoC is targeting vulnerabilities in Palo Alto PAN-OS, specifically CVE-2024-0012 and CVE-2024-9474. This script automates the exploitation process, including payload creation, chunked delivery, and seamless command execution.
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗GitHub PoC★ 2
Palo Alto Networks PAN-OS(CVE-2024-9474) POC
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open ↗GitHub PoC★ 1
KiviCare – Clinic & Patient Management System (EHR) WordPress Plugin Unauthenticated SQL Injection PoC
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection
61RISK
open ↗GitHub PoC
Cái này dựng lên với mục đích cho ae tham khảo, chê thì đừng có xem. :))))
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RISK
open ↗GitHub PoC
An example of a repo that would make use of the CVE-2024-32002
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC★ 1
CVE-2024-55557
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.