Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
13,654 exploits
GitHub PoC95
A Pwn2Own 2024 SpiderMonkey JIT Bug: From Integer Range Inconsistency to Bound Check Elimination then RCE
CVE-2024-29943CRITICAL27 Jun 2024
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RISK
open
GitHub PoC14
CVE-2024-34102: Unauthenticated Magento XXE
CVE-2024-34102CRITICALunder attack27 Jun 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC
This is a simple proof of concept for CVE-2023-49103.
CVE-2023-49103CRITICALunder attack27 Jun 2024
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies
100RISK
open
GitHub PoC8
🆘New Windows Kernel Priviledge Escalation Vulnerability
CVE-2024-30088HIGHunder attackransomware27 Jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC1
Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions
CVE-2024-28995HIGHunder attack26 Jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
GitHub PoC1
ggfzx/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware26 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
zerobytesecure/CVE-2019-19781
CVE-2019-19781CRITICALunder attackransomware25 Jun 2024
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
CVE-2021-34527HIGHunder attackransomware25 Jun 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784
CVE-2023-38831HIGHunder attackransomware25 Jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
CVE-2024-6028 Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
CVE-2024-6028CRITICAL25 Jun 2024
Quiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
68RISK
open
GitHub PoC1
The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.
CVE-2019-905325 Jun 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC290
tykawaii98/CVE-2024-30088
CVE-2024-30088HIGHunder attackransomware24 Jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
CVE-2018-9995
CVE-2018-999524 Jun 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC45
Exploit for the CVE-2024-5806
CVE-2024-5806CRITICAL24 Jun 2024
MOVEit Transfer Authentication Bypass Vulnerability
85RISK
open
GitHub PoC1
This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)
CVE-2024-4577CRITICALunder attackransomware24 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
Proof of concept of CVE-2024-29868 affecting Apache StreamPipes from 0.69.0 through 0.93.0
CVE-2024-29868CRITICAL24 Jun 2024
Apache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
63RISK
open
GitHub PoC
PoC and analysis for Kibana Prototype Pollution RCE (CVE-2019-7609).
CVE-2019-7609CRITICALunder attack23 Jun 2024
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC2
☣️ This repository contains the description and a proof of concept for CVE-2024-34313
CVE-2024-34313CRITICAL23 Jun 2024
An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a pu
48RISK
open
GitHub PoC40
tykawaii98/CVE-2024-21338_PoC
CVE-2024-21338HIGHunder attackransomware23 Jun 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC4
Exploit for CVE-2024-28999 SolarWinds Platform Race Condition Vulnerability - login page
CVE-2024-28999MEDIUM22 Jun 2024
SolarWinds Platform Race Condition Vulnerability
38RISK
open
GitHub PoC
CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook
CVE-2023-23397CRITICALunder attack22 Jun 2024
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
A tool for vulnerability detection and exploitation tool for CVE-2024-31982
CVE-2024-31982CRITICAL22 Jun 2024
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RISK
open
GitHub PoC10
POC for CVE-2024-31982: XWiki Platform Remote Code Execution > 14.10.20
CVE-2024-31982CRITICAL22 Jun 2024
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RISK
open
GitHub PoC1
NanoWraith/CVE-2024-31982
CVE-2024-31982CRITICAL22 Jun 2024
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RISK
open
GitHub PoC6
Exploiter a Vulnerability detection and Exploitation tool for CVE-2024-29973 with Asychronous Performance.
CVE-2024-29973CRITICAL21 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
GitHub PoC
PoC and Bulk Scanner for CVE-2024-29973
CVE-2024-29973CRITICAL21 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
GitHub PoC
phanthibichtram12/CVE-2022-1565
CVE-2022-1565HIGH21 Jun 2024
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RISK
open
GitHub PoC5
PoC of CVE-2024-37759
CVE-2024-37759CRITICAL21 Jun 2024
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerabi
48RISK
open
GitHub PoC
CYBER-WARRIOR-SEC/CVE-2024-28397-js2py-Sandbox-Escape
CVE-2024-28397MEDIUM21 Jun 2024
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC1
rdoix/cve-2024-21762-checker
CVE-2024-21762CRITICALunder attackransomware20 Jun 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
previouspage 215 / 456next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.