Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
13,618 exploits
GitHub PoC
a proof of concept of the CVE-2024-27198 which infect jetbrains teamCity
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗GitHub PoC
kkhackz0013/CVE-2024-36401
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗GitHub PoC
lemonadern/poc-cve-2019-14287
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open ↗GitHub PoC
Gilospy/CVE-2022-26134
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC★ 1
PoC for RCE in SQLPad (CVE-2022-0944)
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open ↗GitHub PoC★ 1
CVE-2021-40539:ADSelfService Plus RCE漏洞
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open ↗GitHub PoC
CVE-2021-40539:ADSelfService Plus RCE漏洞
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open ↗GitHub PoC
intel365/CVE-2024-7593
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open ↗GitHub PoC★ 2
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RISK
open ↗GitHub PoC★ 1
OxLmahdi/cve-2024-5932
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open ↗GitHub PoC★ 1
test_private_CVE
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open ↗GitHub PoC★ 1
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
63RISK
open ↗GitHub PoC
Checkpoint SQL Injection via Time-Based Attack (CVE-2024-9465)
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISK
open ↗GitHub PoC★ 2
intel365/CVE-2024-29973
** UNSUPPORTED WHEN ASSIGNED **
The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open ↗GitHub PoC★ 6
p33d/CVE-2024-9441
Linear eMerge e3-Series Forgot Password Command Injection
60RISK
open ↗GitHub PoC★ 5
is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open ↗GitHub PoC★ 44
Proof of Concept Exploit for CVE-2024-9464
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
70RISK
open ↗GitHub PoC★ 2
intel365/CVE-2024-2876
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open ↗GitHub PoC★ 31
Proof of Concept Exploit for CVE-2024-9465
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISK
open ↗GitHub PoC★ 17
CVE-2024-38077: Remote Code Execution Vulnerability in Windows Remote Desktop Licensing Service
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 3
is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗GitHub PoC★ 27
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISK
open ↗GitHub PoC
bka/magento-cve-2024-34102-exploit-cosmicstring
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac
Booking Calendar <= 9.9 - Unauthenticated SQL Injection
48RISK
open ↗GitHub PoC★ 1
Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 1
Agilevatester/FlaskCache_CVE-2021-33026_POC
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
48RISK
open ↗GitHub PoC
wargame, CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.