Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
13,689 exploits
GitHub PoC★ 3
Exploit tool to validate CVE-2024-24919 vulnerability on Checkpoint Firewall VPNs
Information disclosure
100RISK
open ↗GitHub PoC★ 16
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-24919, a critical vulnerability discovered in Check Point SVN. The vulnerability allows for reading system files. CVE ID: CVE-2024-24919
Information disclosure
100RISK
open ↗GitHub PoC
quartz with CVE-2019-13990
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attack
53RISK
open ↗GitHub PoC★ 1
El script explota una vulnerabilidad de deserialización insegura en Apache ActiveMQ (CVE-2023-46604)
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗GitHub PoC
CVE-2024-32002 poc test
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC★ 1
Exploit for CVE-2024-4956 affecting all previous Sonatype Nexus Repository 3.x OSS/Pro versions up to and including 3.68.0
Nexus Repository 3 - Path Traversal
61RISK
open ↗GitHub PoC★ 3
Quick and simple script that takes as input a file with multiple URLs to check for the CVE-2024-24919 vulnerability in CHECKPOINT
Information disclosure
100RISK
open ↗GitHub PoC★ 7
Nuclei Template to discover CVE-2024-24919. A path traversal vulnerability in CheckPoint SSLVPN.
Information disclosure
100RISK
open ↗GitHub PoC★ 5
confluence rce (CVE-2021-26084, CVE-2022-26134, CVE-2023-22527)
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC★ 5
confluence rce (CVE-2021-26084, CVE-2022-26134, CVE-2023-22527)
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open ↗GitHub PoC
CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗GitHub PoC★ 12
Эксплойт для уязвимости CVE-2024-0039 на Android, который позволяет выполнять произвольный код через MP4 файл. Этот репозиторий создан для образовательных целей.
In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This
48RISK
open ↗GitHub PoC★ 5
confluence rce (CVE-2021-26084, CVE-2022-26134, CVE-2023-22527)
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC
CVE-2020-5377: Dell OpenManage Server Administrator File Read
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RISK
open ↗GitHub PoC
Log4Shell (CVE-2021-44228) PoC Application
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 1
Hoanle396/CVE-2021-44228-demo
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 1
The Country State City Dropdown CF7 WordPress plugin (versions up to 2.7.2) is vulnerable to SQL Injection via 'cnt' and 'sid' parameters. Insufficient escaping and lack of preparation in the SQL query allow unauthenticated attackers to append queries, potentially extracting sensitive database information.
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISK
open ↗GitHub PoC★ 5
POC iteration for CVE-2024-23108 which can use -l for list input
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RISK
open ↗GitHub PoC★ 1
Goplush/CVE-2024-32002-git-rce
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC★ 1
Microsoft Windows 'HTTP.sys' - Remote Code Execution
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open ↗GitHub PoC★ 3
CVE-2024-4956 : Nexus Repository Manager 3 poc exploit
Nexus Repository 3 - Path Traversal
61RISK
open ↗GitHub PoC★ 2
Demo for CVE-2023-43654 - Remote Code Execution in PyTorch TorchServe
TorchServe Server-Side Request Forgery
75RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.