Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
13,689 exploits
GitHub PoC11
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793
CVE-2023-42793CRITICALunder attackransomware24 Apr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.
CVE-2024-3400CRITICALunder attackransomware24 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
CVE-2019-9670CRITICALunder attack24 Apr 2024
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
GitHub PoC4
PoC exploit for GLPI - Command injection using a third-party library script
CVE-2022-35914CRITICALunder attack24 Apr 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
GitHub PoC
mrrobot0o/CVE-2024-3273-
CVE-2024-3273HIGHunder attack23 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC
A basic script that exploits CVE-2011-2523
CVE-2011-252323 Apr 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC6
A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read
CVE-2018-14847CRITICALunder attack22 Apr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC1
A final project for "Network Security" class at NYCU (National Yang Ming Chiao Tung University, Taiwan). Exploiting a CVE in "EasyAppointments" software.
CVE-2022-0482CRITICAL22 Apr 2024
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RISK
open
GitHub PoC36
CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
CVE-2024-27198CRITICALunder attackransomware22 Apr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC
CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)
CVE-2022-24716HIGH22 Apr 2024
Path traversal in Icinga Web 2
78RISK
open
GitHub PoC216
Oracle VirtualBox Elevation of Privilege (Local Privilege Escalation) Vulnerability
CVE-2024-21111HIGH22 Apr 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISK
open
GitHub PoC
CVE-2023-0386 包含所需运行库
CVE-2023-0386HIGHunder attack22 Apr 2024
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC
TYuan0816/cve-2023-44487
CVE-2023-44487HIGHunder attack22 Apr 2024
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC
SOPlanning 1.52.00 CSRF/SQLi/XSS (CVE-2024-33722, CVE-2024-33724)
CVE-2024-33722MEDIUM22 Apr 2024
SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
33RISK
open
GitHub PoC
Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation
CVE-2024-3400CRITICALunder attackransomware21 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 Implementation
CVE-2023-42793CRITICALunder attackransomware21 Apr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
PoC for CVE-2024-24576 vulnerability "BatBadBut"
CVE-2024-24576CRITICAL21 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC2
Python POC for CVE-2023-6019 taken from https://huntr.com/bounties/d0290f3c-b302-4161-89f2-c13bb28b4cfe
CVE-2023-6019CRITICAL21 Apr 2024
Ray Command Injection in cpu_profile Parameter
85RISK
open
GitHub PoC
bde574786/Sequelize-1day-CVE-2023-25813
CVE-2023-25813CRITICAL21 Apr 2024
SQL Injection via replacements in sequelize
48RISK
open
GitHub PoC1
WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)
CVE-2024-25600CRITICAL20 Apr 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
Gaurav1020/CVE-2024-24576-PoC-Rust
CVE-2024-24576CRITICAL20 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC1
H3C ER8300G2-X config download
CVE-2024-32238CRITICAL20 Apr 2024
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RISK
open
GitHub PoC
asdfjkl11/CVE-2024-32238
CVE-2024-32238CRITICAL20 Apr 2024
H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse
75RISK
open
GitHub PoC
Finding Palo Alto devices vulnerable to CVE-2024-3400.
CVE-2024-3400CRITICALunder attackransomware19 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
Extract useful information from PANOS support file for CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware19 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
ASG-CASTLE/CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware19 Apr 2024
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC2
Proof of concept for CVE-2022-0847
CVE-2022-0847HIGHunder attack19 Apr 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
Whiteh4tWolf/CVE-2024-1651-PoC
CVE-2024-1651CRITICAL19 Apr 2024
Torrentpier 2.4.1 - RCE
60RISK
open
GitHub PoC
ASG-CASTLE/CVE-2021-4034
CVE-2021-4034HIGHunder attack19 Apr 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC5
XZ Utils CVE-2024-3094 POC for Kubernetes
CVE-2024-3094CRITICAL18 Apr 2024
Xz: malicious code in distributed source
70RISK
open
previouspage 230 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.