Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
13,687 exploits
GitHub PoC5
CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC25
Ivanti EPM SQL Injection Remote Code Execution Vulnerability
CVE-2024-29824CRITICALunder attack12 Jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISK
open
GitHub PoC4
jakabakos/CVE-2024-27348-Apache-HugeGraph-RCE
CVE-2024-27348CRITICALunder attack12 Jun 2024
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
GitHub PoC
Rejetto http File Server 2.3.x (Reverse shell)
CVE-2014-6287CRITICALunder attack12 Jun 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC
raytran54/CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware12 Jun 2024
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
HPT-Intern-Task-Submission/CVE-2022-46169
CVE-2022-46169CRITICALunder attack12 Jun 2024
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Basic POC to test CVE-2024-3094 vulnerability inside K8s cluster
CVE-2024-3094CRITICAL11 Jun 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
CVE-2022-36446 POC 실습
CVE-2022-3644611 Jun 2024
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RISK
open
GitHub PoC4
NanoWraith/CVE-2024-23692
CVE-2024-23692CRITICALunder attack11 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
GitHub PoC29
CVE-2024-37051 poc and exploit
CVE-2024-37051CRITICAL11 Jun 2024
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ
48RISK
open
GitHub PoC1
SalehLardhi/CVE-2024-24919
CVE-2024-24919HIGHunder attackransomware11 Jun 2024
Information disclosure
100RISK
open
GitHub PoC
PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
CVE-2024-4577CRITICALunder attackransomware11 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
This is a PoC for PHP CVE-2024-4577.
CVE-2024-4577CRITICALunder attackransomware11 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
feely666/CVE-2024-1086
CVE-2024-1086HIGHunder attackransomware10 Jun 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC1
Vulnerability check script for CVE-2024-37393 (SecurEnvoy MFA 9.4.513)
CVE-2024-37393CRITICAL10 Jun 2024
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-suppl
63RISK
open
GitHub PoC
paradox0909/cve-2022-30333_online_rar_extracor
CVE-2022-30333HIGHunder attackransomware10 Jun 2024
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RISK
open
GitHub PoC90
Veeam Backup Enterprise Manager Authentication Bypass (CVE-2024-29849)
CVE-2024-29849CRITICAL10 Jun 2024
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
53RISK
open
GitHub PoC3
Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.
CVE-2021-44228CRITICALunder attackransomware09 Jun 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC16
POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal
CVE-2024-4956HIGH09 Jun 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC9
POC - CVE-2024–24919 - Check Point Security Gateways
CVE-2024-24919HIGHunder attackransomware09 Jun 2024
Information disclosure
100RISK
open
GitHub PoC10
A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE)
CVE-2024-4577CRITICALunder attackransomware09 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC12
Authentication Bypass Vulnerability — CVE-2024–4358 — Telerik Report Server 2024
CVE-2024-4358CRITICALunder attack09 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
GitHub PoC3
itzheartzz/MASS-CVE-2024-27956
CVE-2024-27956CRITICAL09 Jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC35
PHP CGI Argument Injection vulnerability
CVE-2024-4577CRITICALunder attackransomware09 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
python poc编写练手,可以对单个目标或批量检测
CVE-2024-4577CRITICALunder attackransomware09 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
J4F9S5D2Q7/CVE-2023-43208-MIRTHCONNECT
CVE-2023-43208CRITICALunder attackransomware09 Jun 2024
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.
CVE-2024-31819CRITICAL09 Jun 2024
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath
68RISK
open
GitHub PoC3
CVE-2024-4577 Exploit POC
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC9
Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands.
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC164
[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
previouspage 219 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.