Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,534GitHub PoC 13,654VulnCheck XDB 8,213Nuclei 4,218Metasploit 3,464✓ verified onlyrecentpopularrisk
13,654 exploits
GitHub PoC★ 16
p0in7s/CVE-2024-38475
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open ↗GitHub PoC
CVE-2024-7094 Vulnerability checker
JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution
60RISK
open ↗GitHub PoC
WTN-arny/CVE-2024-37085
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RISK
open ↗GitHub PoC
Chamilo LMS Unauthenticated Big Upload File that allows remote code execution
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC
POC
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC★ 87
Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
Comodo
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISK
open ↗GitHub PoC
PoC about CVE-2024-27198
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗GitHub PoC★ 7
CVE-2024-38077,仅支持扫描测试~
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
1amthebest1/CVE-2023-27372
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open ↗GitHub PoC
MahdiOsman/CVE-2018-15473-SNMPv1-2-Community-String-Vulnerability-Testing
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 13
mitigation script by disabling ipv6 of all interfaces
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 1
An issue in Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity
48RISK
open ↗GitHub PoC
Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open ↗GitHub PoC★ 3
This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where I could use gopher to make internal requests on Zabbix vulnerable to RCE.
Time Based SQL Injection in Zabbix Server Audit Log
70RISK
open ↗GitHub PoC★ 125
fortra/CVE-2024-30051
Windows DWM Core Library Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC
jFriedli/CVE-2023-3897
Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
33RISK
open ↗GitHub PoC★ 3
This is my exploit for CVE-2024-22120, which involves an SSRF vulnerability inside an XXE with a Gopher payload.
Time Based SQL Injection in Zabbix Server Audit Log
70RISK
open ↗GitHub PoC★ 4
Adobe Commerce XXE exploit
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC★ 3
K7 Ultimate Security < v17.0.2019 "K7RKScan.sys" Null Pointer Dereference PoC
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of
33RISK
open ↗GitHub PoC
This repository contains detailed documentation and code related to the exploitation, detection, and mitigation of two significant vulnerabilities: CVE-2020-0796 (SMBGhost) and Print Spooler.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗GitHub PoC
CVE-2024-37085 unauthenticated shell upload to full administrator on domain-joined esxi hypervisors.
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RISK
open ↗GitHub PoC
This script is a proof-of-concept exploit for pfBlockerNG <= 2.1.4_26 that allows for remote code execution. It takes a single target URL or a list of URLs, tries to upload a shell using multiple payloads, executes a command, and then deletes the shell.
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RISK
open ↗GitHub PoC
A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗GitHub PoC★ 1
Wonder CMS RCE (XSS)
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open ↗GitHub PoC
CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RISK
open ↗GitHub PoC★ 2
Perform With Massive Apache OFBiz Zero-Day Scanner & RCE
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.