Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
13,618 exploits
GitHub PoC12
math-x-io/CVE-2024-54152-poc
CVE-2024-54152CRITICAL30 Dec 2024
Angular Expressions - Remote Code Execution when using locals
48RISK
open
GitHub PoC4
AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF challenges. Strictly for authorized and educational use only!
CVE-2017-0144HIGHunder attackransomware30 Dec 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
luongchivi/Preproduce-CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware30 Dec 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
PoC for CVE-2024-21182
CVE-2024-21182HIGHunder attack29 Dec 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RISK
open
GitHub PoC2
PoC for CVE-2024-21182
CVE-2024-21182HIGHunder attack29 Dec 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
83RISK
open
GitHub PoC2
Hi this is a revised and enhanced code for CVE-2019-0232
CVE-2019-023229 Dec 2024
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC1
CVE-2024-50379-exp
CVE-2024-50379CRITICAL28 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
GitHub PoC
Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE
CVE-2024-8069MEDIUMunder attack28 Dec 2024
Limited remote code execution with privilege of a NetworkService Account access
68RISK
open
GitHub PoC
A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized domain controller access.
CVE-2020-1472MEDIUMunder attackransomware28 Dec 2024
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. (CRITICAL)
CVE-2024-7954CRITICAL28 Dec 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC1
Nxploited/CVE-2024-9234
CVE-2024-9234CRITICAL28 Dec 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC3
CVE-2023-40028 PoC Exploit
CVE-2023-40028MEDIUM28 Dec 2024
Arbitrary file read via symlinks in Ghost
45RISK
open
GitHub PoC
Nxploited/CVE-2024-9933
CVE-2024-9933CRITICAL27 Dec 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISK
open
GitHub PoC
Malware Analysis CVE-2017-11882
CVE-2017-11882HIGHunder attackransomware26 Dec 2024
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
Testing the latset Apache Tomcat CVE-2024-50379 Vuln
CVE-2024-50379CRITICAL26 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
GitHub PoC
AleksaZatezalo/CVE-2020-14882
CVE-2020-14882CRITICALunder attack26 Dec 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC2
Drupal CVE-2024-45440
CVE-2024-45440MEDIUM26 Dec 2024
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash
48RISK
open
GitHub PoC
yoohhuu/Rocket-Chat-3.12.1-PoC-CVE-2021-22911-
CVE-2021-2291126 Dec 2024
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC
A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1
CVE-2024-23334MEDIUM25 Dec 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC5
WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本
CVE-2024-9047CRITICAL25 Dec 2024
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISK
open
GitHub PoC4
This repository contains a Python script designed to exploit CVE-2024-50379, a vulnerability that allows attackers to upload a JSP shell to a vulnerable server and execute arbitrary commands remotely. This exploit is particularly useful when the /uploads directory is either unprotected or not present on the target server.
CVE-2024-50379CRITICAL25 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
GitHub PoC1
UnionTech-Software/libtheora-CVE-2024-56431-PoC
CVE-2024-56431CRITICAL25 Dec 2024
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: th
48RISK
open
GitHub PoC
A PoC exploit for CVE-2024-10914 - D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL24 Dec 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC1
The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.
CVE-2024-9290CRITICAL24 Dec 2024
Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
48RISK
open
GitHub PoC3
Unauthenticated Local File Inclusion
CVE-2024-12209CRITICAL24 Dec 2024
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
68RISK
open
GitHub PoC1
CVE-2024-50379利用
CVE-2024-50379CRITICAL23 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
GitHub PoC
hiteshpatra/CVE-2024-53677
CVE-2024-53677CRITICAL23 Dec 2024
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC83
tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp
CVE-2024-50379CRITICAL23 Dec 2024
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
GitHub PoC7
CVE-2024-50623 POC - Cleo Unrestricted file upload and download
CVE-2024-50623CRITICALunder attackransomware23 Dec 2024
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISK
open
GitHub PoC4
CVE-2024-56145 SSTI to RCE - twig templates
CVE-2024-56145CRITICALunder attack22 Dec 2024
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISK
open
previouspage 184 / 454next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.