Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
13,618 exploits
GitHub PoC3
WP Sessions Time Monitoring Full Automatic <= 1.0.9 - Unauthenticated SQL Injection
CVE-2024-49681CRITICAL09 Nov 2024
WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.0.9 - SQL Injection vulnerability
48RISK
open
GitHub PoC
sea-middle/cve-2023-25813
CVE-2023-25813CRITICAL09 Nov 2024
SQL Injection via replacements in sequelize
48RISK
open
GitHub PoC
Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload
CVE-2024-50473CRITICAL09 Nov 2024
WordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
CVE-2024-4898CRITICAL08 Nov 2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
63RISK
open
GitHub PoC
Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover
CVE-2024-50477CRITICAL08 Nov 2024
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISK
open
GitHub PoC
WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion
CVE-2024-10470CRITICAL08 Nov 2024
WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
60RISK
open
GitHub PoC
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload
CVE-2024-50427CRITICAL08 Nov 2024
WordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC1
0xR00/CVE-2024-23334
CVE-2024-23334MEDIUM07 Nov 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC1
cbyerpanel rce exploit
CVE-2024-51567CRITICALunder attackransomware07 Nov 2024
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISK
open
GitHub PoC1
AliHj98/cve-2024-38063-Anonyvader
CVE-2024-38063CRITICAL07 Nov 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC98
Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575
CVE-2024-47575CRITICALunder attack07 Nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open
GitHub PoC
CVE-2023-25813 Vulnerability Reproduction - SQL Injection in Sequelize
CVE-2023-25813CRITICAL07 Nov 2024
SQL Injection via replacements in sequelize
48RISK
open
GitHub PoC
Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress
CVE-2023-6553CRITICAL07 Nov 2024
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
GitHub PoC
pedrochalegre7/CVE-2024-4367-pdf-sample
CVE-2024-4367MEDIUM06 Nov 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
pbj2647/CVE-2023-25813
CVE-2023-25813CRITICAL06 Nov 2024
SQL Injection via replacements in sequelize
48RISK
open
GitHub PoC25
CVE-2024-4577 RCE PoC
CVE-2024-4577CRITICALunder attackransomware06 Nov 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC6
WP REST API FNS <= 1.0.0 - Privilege Escalation
CVE-2024-49328CRITICAL06 Nov 2024
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RISK
open
GitHub PoC4
This repository contains a Crystallographic Information File (CIF) intended for use on the "Chemistry" machine on Hack The Box (HTB).
CVE-2024-23346CRITICAL05 Nov 2024
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open
GitHub PoC3
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9932CRITICAL05 Nov 2024
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload
CVE-2024-50482CRITICAL05 Nov 2024
WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
CVE-2024-9933CRITICAL05 Nov 2024
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISK
open
GitHub PoC2
Meetup <= 0.1 - Authentication Bypass via Account Takeover
CVE-2024-50483CRITICAL05 Nov 2024
WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
48RISK
open
GitHub PoC
1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover
CVE-2024-50478CRITICAL05 Nov 2024
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
48RISK
open
GitHub PoC
guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
CVE-2022-22965CRITICALunder attack05 Nov 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update
CVE-2024-50476CRITICAL04 Nov 2024
WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISK
open
GitHub PoC
Signup Page <= 1.0 - Unauthenticated Arbitrary Options Update
CVE-2024-50475CRITICAL04 Nov 2024
WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability
48RISK
open
GitHub PoC3
WP Query Console <= 1.0 - Unauthenticated Remote Code Execution
CVE-2024-50498CRITICAL04 Nov 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open
GitHub PoC
Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)
CVE-2024-37383MEDIUMunder attack03 Nov 2024
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISK
open
GitHub PoC
ahmetramazank/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware03 Nov 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
77Philly/CVE-2024-7456scripts
CVE-2024-7456CRITICAL02 Nov 2024
SQL Injection in lunary-ai/lunary
48RISK
open
previouspage 192 / 454next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.