Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
13,618 exploits
GitHub PoC1
CVE-2024-54761 PoC
CVE-2024-54761MEDIUM15 Nov 2024
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RISK
open
GitHub PoC2
Bash script to automate Local File Inclusion (LFI) attacks on aiohttp server version 3.9.1.
CVE-2024-23334MEDIUM14 Nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC
CiscoRV320Dump CVE-2019-1653 - Automatition.
CVE-2019-1653HIGHunder attack14 Nov 2024
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RISK
open
GitHub PoC
Fortigate SSL VPN buffer overflow exploit
CVE-2023-27997CRITICALunder attackransomware14 Nov 2024
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC1
common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions leads to (RCE)
CVE-2024-52302HIGH14 Nov 2024
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
41RISK
open
GitHub PoC4
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass
CVE-2024-10924CRITICAL14 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
This script is specifically designed to solve the challenge on PentesterLab for the CVE-2013-0156 exploit
CVE-2013-015613 Nov 2024
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
GitHub PoC
Ivanti Cloud Services Appliance - Path Traversal
CVE-2024-8963CRITICALunder attack13 Nov 2024
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISK
open
GitHub PoC
CVE-2024-10914_Manual testing with burpsuite
CVE-2024-10914CRITICAL13 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
https://nvd.nist.gov/vuln/detail/CVE-2023-4220
CVE-2023-4220HIGH13 Nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC2
working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln
CVE-2021-21425CRITICAL13 Nov 2024
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISK
open
GitHub PoC1
Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability
CVE-2024-21534CRITICAL13 Nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RISK
open
GitHub PoC
fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command
CVE-2021-3156HIGHunder attack13 Nov 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
Attempt at making the CVE-2024-3400 initial exploit (for educational purposes)
CVE-2024-3400CRITICALunder attackransomware12 Nov 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
harshtech123/cve-2020-24881
CVE-2020-2488112 Nov 2024
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RISK
open
GitHub PoC1
Python POC for CVE-2024-32640 Mura CMS SQLi
CVE-2024-32640CRITICAL12 Nov 2024
MasaCMS SQL Injection vulnerability
85RISK
open
GitHub PoC
CVE-2022-21661 docker and poc
CVE-2022-21661HIGH12 Nov 2024
SQL injection in WordPress
78RISK
open
GitHub PoC1
This repository contains an exploit for CVE-2019-16278 in Nostromo Web Server 1.9.6, allowing remote code execution via a directory traversal vulnerability. The script uses pwntools to establish a reverse shell. For educational and authorized testing use only.
CVE-2019-16278CRITICALunder attack12 Nov 2024
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC
CVE: 2015-1328 On python test
CVE-2015-132812 Nov 2024
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC
uthrasri/CVE-2018-14881_no_patch
CVE-2018-14881CRITICAL11 Nov 2024
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTA
48RISK
open
GitHub PoC1
oxapavan/CVE-2023-4220-HTB-PermX
CVE-2023-4220HIGH10 Nov 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC48
POC - CVE-2024–10914- Command Injection Vulnerability in `name` parameter for D-Link NAS
CVE-2024-10914CRITICAL10 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
CVE-2024-47062 PoC
CVE-2024-47062CRITICAL10 Nov 2024
Multiple SQL Injections and ORM Leak in navidrome
63RISK
open
GitHub PoC
In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10
CVE-2021-44228CRITICALunder attackransomware10 Nov 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
To test elasticsearch vulnerabillity on newer version of debian
CVE-2015-1427CRITICALunder attack10 Nov 2024
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISK
open
GitHub PoC
Automatic Translation <= 1.0.4 - Unauthenticated Arbitrary File Upload
CVE-2024-50493CRITICAL10 Nov 2024
WordPress Automatic Translation plugin <= 1.0.4 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC1
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
CVE-2024-10586CRITICAL10 Nov 2024
Debug Tool <= 2.2 - Unauthenticated Arbitrary File Creation
48RISK
open
GitHub PoC
sea-middle/cve-2023-25813
CVE-2023-25813CRITICAL09 Nov 2024
SQL Injection via replacements in sequelize
48RISK
open
GitHub PoC
WP Dropbox Dropins <= 1.0 - Unauthenticated Arbitrary File Upload
CVE-2024-49607CRITICAL09 Nov 2024
WordPress WP Dropbox Dropins plugin <= 1.0 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload
CVE-2024-50473CRITICAL09 Nov 2024
WordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability
48RISK
open
previouspage 191 / 454next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.