Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
13,654 exploits
GitHub PoC1
Chamilo LMS Unauthenticated Remote Code Execution
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
CVE-2023-4220HIGH07 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC7
PoC - PHP CGI Argument Injection CVE-2024-4577 (Scanner and Exploit)
CVE-2024-4577CRITICALunder attackransomware06 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC56
Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit
CVE-2024-36401CRITICALunder attack06 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC1
Exploiter a Vulnerability detection and Exploitation tool for GeoServer Unauthenticated Remote Code Execution CVE-2024-36401.
CVE-2024-36401CRITICALunder attack05 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC4
POC
CVE-2024-36401CRITICALunder attack05 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC2
SSH EXPLOIT BYPASS AUTH SSH
CVE-2024-3094CRITICAL05 Jul 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC59
GNU IFUNC is the real culprit behind CVE-2024-3094
CVE-2024-3094CRITICAL05 Jul 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC373
HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the Web interface Version 3.1.3.150324 + CVE-2021-36260 Detection
CVE-2021-36260CRITICALunder attack05 Jul 2024
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC
puckiestyle/CVE-2023-27532-RCE-Only
CVE-2023-27532HIGHunder attackransomware05 Jul 2024
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISK
open
GitHub PoC3
CVE-2024-4040 PoC
CVE-2024-4040CRITICALunder attack05 Jul 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC10
HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).
CVE-2024-6387HIGH05 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC2
Quick regreSSHion checker (based on software version) for nuclei CVE-2024-6387
CVE-2024-6387HIGH05 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC5
Vulnerability remediation and mitigationCVE-2024-6387
CVE-2024-6387HIGH05 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
imv7/CVE-2024-6387
CVE-2024-6387HIGH05 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
TeamCity RCE for Linux (CVE-2023-42793)
CVE-2023-42793CRITICALunder attackransomware05 Jul 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC1
CVE-2024-37770
CVE-2024-37770CRITICAL05 Jul 2024
14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This
48RISK
open
GitHub PoC44
该漏洞存在于 NtQueryInformationToken 函数中,特别是在处理AuthzBasepCopyoutInternalSecurityAttributes 函数时,该漏洞源于内核在操作对象时对锁定机制的不当管理,这一失误可能导致恶意实体意外提升权限。
CVE-2024-30088HIGHunder attackransomware05 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
CVE-2024-39943CRITICAL05 Jul 2024
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth
60RISK
open
GitHub PoC
Provides instructions for using the script to check if your OpenSSH installation is vulnerable to CVE-2024-6387
CVE-2024-6387HIGH04 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
xzx482/CVE-2024-1086
CVE-2024-1086HIGHunder attackransomware04 Jul 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC
CVE-2017-12617
CVE-2017-12617HIGHunder attack04 Jul 2024
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RISK
open
GitHub PoC1
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
CVE-2024-6387HIGH04 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
rewrited SSH Exploit for CVE-2024-6387 (regreSSHion)
CVE-2024-6387HIGH04 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
iamz24/CVE-2021-3493_CVE-2022-3357
CVE-2021-3493HIGHunder attack04 Jul 2024
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC4
lala-amber/CVE-2024-6387
CVE-2024-6387HIGH04 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
sms2056/CVE-2024-6387
CVE-2024-6387HIGH04 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
Welcome to the CVE-2024-6387 OpenSSH Vulnerability Checker repository! This project offers multiple scripts to check the installed version of OpenSSH on your system and determine if it is vulnerable to CVE-2024-6387. It supports various environments, including Ubuntu, Mac, and Windows.
CVE-2024-6387HIGH04 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
CVE-2024-6387_Check 是一款轻量级、高效的工具,旨在识别运行易受攻击的 OpenSSH 版本的服务器,专门针对最近发现的regreSSHion漏洞 (CVE-2024-6387)。此脚本有助于快速扫描多个 IP 地址、域名和 CIDR 网络范围,以检测潜在漏洞并确保您的基础设施安全。
CVE-2024-6387HIGH04 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
This repository investigates the exploitation of CVE-2023-34362 in the MOVEit file transfer server by the TA505 (Cl0p) ransomware group. It explores the group's tactics and past campaigns targeting file transfer applications, aiming to enhance understanding and defensive measures against such threats.
CVE-2023-34362CRITICALunder attackransomware04 Jul 2024
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
previouspage 211 / 456next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.