Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
13,627 exploits
GitHub PoC
bryanqb07/CVE-2023-32315
Openfire administration console authentication bypass
100RISK
open ↗GitHub PoC★ 1
This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 4
Masamuneee/CVE-2024-4367-Analysis
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC★ 1
brownpanda29/Cve-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 3
Authenticated Code execution
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File
48RISK
open ↗GitHub PoC★ 1
(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC★ 1
Adobe ColdFusion CVE-2023-26360/CVE-2023-29298 自动化实现反弹
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open ↗GitHub PoC★ 1
Raffli-Dev/CVE-2023-41425
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open ↗GitHub PoC
ImageMagick 7.1.0-49 vulnerable to Information Disclosure
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open ↗GitHub PoC
ps-interactive/cve-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 8
This module exploits a vulnerability in the target service identified as CVE-2023-42115.
Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
48RISK
open ↗GitHub PoC★ 9
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open ↗GitHub PoC
Yowise/CVE-2022-26923
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 9
This is a C language program designed to test the Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063). It sends specially crafted IPv6 packets with embedded shellcode to exploit the vulnerability.
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 30
poc code for CVE-2024-38080
Windows Hyper-V Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC★ 43
CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 25
CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 11
POC for CVE-2023-29360
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISK
open ↗GitHub PoC
🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨 #Cybersecurity #SOCAnalyst #LetsDefend
Information disclosure
100RISK
open ↗GitHub PoC
Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0
SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the usern
48RISK
open ↗GitHub PoC★ 35
sinsinology/CVE-2024-6670
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
100RISK
open ↗GitHub PoC★ 140
exploits for CVE-2024-20017
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote cod
60RISK
open ↗GitHub PoC★ 23
Proof of concept : CVE-2024-1071: WordPress Vulnerability Exploited
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISK
open ↗GitHub PoC
A POC demo on CVE-2023-38831
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗GitHub PoC★ 7
Fully automated PoC - CVE-2024-25641 - RCE - Cacti < v1.2.26 🌵
Cacti RCE vulnerability when importing packages
85RISK
open ↗GitHub PoC★ 294
tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open ↗GitHub PoC★ 1
In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named "regreSSHion," this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC★ 83
mistymntncop/CVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside
76RISK
open ↗GitHub PoC★ 3
CVE-2019-15107 Webmin unauthenticated RCE
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.