Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
13,654 exploits
GitHub PoC2
基于135端口检测目标是否存在CVE-2024-38077漏洞
CVE-2024-38077CRITICAL10 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
GitHub PoC7
检测RDL服务是否运行,快速排查受影响资产
CVE-2024-38077CRITICAL10 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
GitHub PoC13
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
CVE-2024-7954CRITICAL10 Aug 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC2
A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)
CVE-2024-3105CRITICAL10 Aug 2024
Woody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
48RISK
open
GitHub PoC2
Perform With Massive Apache OFBiz Zero-Day Scanner & RCE
CVE-2024-38856HIGHunder attack10 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC
elliotosama/CVE-2012-2982
CVE-2012-298209 Aug 2024
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
GitHub PoC
jtoalu/CTF-CVE-2019-9053-GTFOBins
CVE-2019-905309 Aug 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
CVE-2024-6782CRITICAL09 Aug 2024
Calibre Remote Code Execution
85RISK
open
GitHub PoC5
it is script designed to interact with a router by sending a payload to its system tools. The script retrieves the router's configuration from environment variables to ensure security. It includes functions for generating an authorization header, sending a payload, and logging the process.
CVE-2022-44149HIGH09 Aug 2024
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
53RISK
open
GitHub PoC9
SecStarBot/CVE-2024-38077-POC
CVE-2024-38077CRITICAL09 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
psl-b/CVE-2024-38077-check
CVE-2024-38077CRITICAL09 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
GitHub PoC223
RDL的堆溢出导致的RCE
CVE-2024-38077CRITICAL09 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
GitHub PoC3
CVE-2024-38077,本仓库仅用作备份,
CVE-2024-38077CRITICAL09 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
GitHub PoC13
远程探测 remote desktop licensing 服务开放情况,用于 CVE-2024-38077 漏洞快速排查
CVE-2024-38077CRITICAL09 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
Sec-Link/CVE-2024-38077
CVE-2024-38077CRITICAL09 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
GitHub PoC5
it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script automates the process of authorization, payload generation, and execution, allowing for remote command execution on the target device.
CVE-2022-45701HIGH09 Aug 2024
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISK
open
GitHub PoC
bolkv/CVE-2024-4320
CVE-2024-4320CRITICAL08 Aug 2024
Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
60RISK
open
GitHub PoC2
exploit que vulnera Jenkins hecho en Python
CVE-2024-25897CRITICAL08 Aug 2024
ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
48RISK
open
GitHub PoC1
An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
CVE-2024-34102CRITICALunder attack08 Aug 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC1
CVE-2024-41651
CVE-2024-41651CRITICAL08 Aug 2024
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func
48RISK
open
GitHub PoC49
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
CVE-2024-38856HIGHunder attack08 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC
This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack. It provides information on the vulnerable code, recommended fixes, and how to extract and decrypt administrative credentials.
CVE-2024-44541CRITICAL07 Aug 2024
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
48RISK
open
GitHub PoC
VanishedPeople/CVE-2017-7269
CVE-2017-7269CRITICALunder attack07 Aug 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC6
CVE-2024-32113 Apache OFBIZ Batch Scanning
CVE-2024-32113CRITICALunder attack07 Aug 2024
Apache OFBiz: Path traversal leading to RCE
100RISK
open
GitHub PoC6
Calibre 远程代码执行(CVE-2024-6782)Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
CVE-2024-6782CRITICAL06 Aug 2024
Calibre Remote Code Execution
85RISK
open
GitHub PoC1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
CVE-2023-4596CRITICAL06 Aug 2024
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC1
Found this on exploit-db, decided to make my own for practice. This exploit will search out the passwd file and print the contents on a vulnerable system.
CVE-2024-40422CRITICAL06 Aug 2024
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISK
open
GitHub PoC1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
CVE-2024-6387HIGH06 Aug 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.
CVE-2023-38831HIGHunder attackransomware06 Aug 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
Abdurahmon3236/CVE-2024-36539
CVE-2024-36539CRITICAL03 Aug 2024
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t
48RISK
open
previouspage 206 / 456next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.