Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
13,689 exploits
GitHub PoC2
Simple CVE-2024-24576 PoC in Julia
CVE-2024-24576CRITICAL14 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC3
A reproduction of CVE-2019-18634, sudo privilege escalation with buffer overflow.
CVE-2019-1863414 Apr 2024
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
GitHub PoC
Vulnerabilidad de palo alto
CVE-2024-3400CRITICALunder attackransomware14 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC13
momika233/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware14 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
cve-2020-1938 Tomcat-Ajp-lfi.git脚本
CVE-2020-1938CRITICALunder attack14 Apr 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC1
Python script for CMS Made Simple 2.1.6 - Remote Code Execution.
CVE-2018-744814 Apr 2024
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RISK
open
GitHub PoC
FoxyProxys/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
MAL-004: Command Injection Bypass for CVE-2020-12641 in Roundcube Webmail
CVE-2020-12641CRITICALunder attack13 Apr 2024
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RISK
open
GitHub PoC
Demonstration of CVE-2020-11023
CVE-2020-11023MEDIUMunder attack13 Apr 2024
Potential XSS vulnerability in jQuery
85RISK
open
GitHub PoC11
Yuvvi01/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
CerTusHack/CVE-2024-3400-PoC
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC71
CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail
CVE-2020-13965MEDIUMunder attack13 Apr 2024
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta
85RISK
open
GitHub PoC2
PoC MinIO vulnerability exploit
CVE-2023-28432HIGHunder attack13 Apr 2024
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
CVE-2024-21413 Setup for CW
CVE-2024-21413CRITICALunder attack13 Apr 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y 5.6.1 de la herramienta de compresión XZ.
CVE-2024-3094CRITICAL13 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC335
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
CVE-2024-21338HIGHunder attackransomware13 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC5
OpenMetadata_RCE (CVE-2024-28255) Batch scan/exploit
CVE-2024-28255CRITICAL12 Apr 2024
Authentication Bypass in OpenMetadata
85RISK
open
GitHub PoC2
adhikara13/CVE-2024-2389
CVE-2024-2389CRITICAL11 Apr 2024
Flowmon Unauthenticated Command Injection Vulnerability
85RISK
open
GitHub PoC2
0xWhoami35/CVE-2023-23752
CVE-2023-23752MEDIUMunder attack11 Apr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC1
Public exploit for CVE-2024-31777
CVE-2024-31777CRITICAL11 Apr 2024
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RISK
open
GitHub PoC1
CVE-2024-24576 PoC for Nim Lang
CVE-2024-24576CRITICAL11 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC50
CVE-2023-6319 proof of concept
CVE-2023-6319CRITICAL11 Apr 2024
Command injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service
48RISK
open
GitHub PoC8
Apache OfBiz vulns
CVE-2024-32113CRITICALunder attack10 Apr 2024
Apache OFBiz: Path traversal leading to RCE
100RISK
open
GitHub PoC1
Ray OS Command Injection RCE(Unauthorized)
CVE-2023-6019CRITICAL10 Apr 2024
Ray Command Injection in cpu_profile Parameter
85RISK
open
GitHub PoC9
brains93/CVE-2024-24576-PoC-Python
CVE-2024-24576CRITICAL10 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC20
CVE-2024-24576 Proof of Concept
CVE-2024-24576CRITICAL10 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
GitHub PoC5
D-Link NAS Command Execution Exploit
CVE-2024-3273HIGHunder attack10 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC5
A PoC exploit for CVE-2024-3273 - D-Link Remote Code Execution RCE
CVE-2024-3273HIGHunder attack09 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC59
Example of CVE-2024-24576 use case.
CVE-2024-24576CRITICAL09 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
previouspage 232 / 457next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.