Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC1
CuteNews 2.1.2 - CVE-2019-11447 Proof-Of-Concept
CVE-2019-1144711 Feb 2024
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open
GitHub PoC
arminarab1999/CVE-2018-9995
CVE-2018-999509 Feb 2024
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC
joshbnewton31080/cve-2022-42889-text4shell
CVE-2022-4288908 Feb 2024
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
POC Badgermeter moni tool - CVE-2024-1301
CVE-2024-1301CRITICAL08 Feb 2024
Multiple Vulnerabilities in Badger Meter's Monitool
48RISK
open
GitHub PoC
CVE-2017-0089 Learn more at National Vulnerability Database (NVD) • CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
CVE-2017-008908 Feb 2024
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RISK
open
GitHub PoC
Yanoro/CVE-2017-11176
CVE-2017-1117608 Feb 2024
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RISK
open
GitHub PoC
PoC to CVE-2023-30547 (Library vm2)
CVE-2023-30547CRITICAL08 Feb 2024
Sandbox Escape in vm2
70RISK
open
GitHub PoC
一款Spring综合漏洞的利用工具,工具目前支持Spring Cloud Gateway RCE(CVE-2022-22947)、Spring Framework RCE (CVE-2022-22965) 的检测以及利用
CVE-2022-22947CRITICALunder attack07 Feb 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC3
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
CVE-2024-23897CRITICALunder attackransomware07 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC61
CVE-2024-20931, this is the bypass of the patch of CVE-2023-21839
CVE-2023-21839HIGHunder attack06 Feb 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC
trustcves/CVE-2024-24398
CVE-2024-24398CRITICAL05 Feb 2024
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker
48RISK
open
GitHub PoC1
CVE-2023-6875 exploit written for Xakep.Ru
CVE-2023-6875CRITICAL05 Feb 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISK
open
GitHub PoC
xMr110/CVE-2022-1040
CVE-2022-1040CRITICALunder attack05 Feb 2024
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RISK
open
GitHub PoC
letsr00t/-2021-LOCALROOT-CVE-2021-22555
CVE-2021-22555HIGHunder attack05 Feb 2024
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC
Shellshock exploit (CVE-2014-6271)
CVE-2014-6271CRITICALunder attack04 Feb 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
semcms存在SQL注入(CVE-2024-25422 )
CVE-2024-25422CRITICAL04 Feb 2024
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info
48RISK
open
GitHub PoC
WLXQqwer/Jenkins-CVE-2024-23897-
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC22
Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC1
GoAnywhere MFT
CVE-2024-0204CRITICAL04 Feb 2024
Authentication Bypass in GoAnywhere MFT
85RISK
open
GitHub PoC2
wechicken456/CVE-2021-4034-CTF-writeup
CVE-2021-4034HIGHunder attack04 Feb 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC5
Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite
CVE-2019-2215HIGHunder attack04 Feb 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC1
Triggering the famous libweb 0day vuln with libfuzzer
CVE-2023-4863HIGHunder attack04 Feb 2024
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC
xMr110/CVE-2020-14882
CVE-2020-14882CRITICALunder attack04 Feb 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
CharonDefalt/Juniper-exploit-CVE-2023-36845
CVE-2023-36845CRITICALunder attack03 Feb 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC27
CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit
CVE-2024-21893HIGHunder attackransomware03 Feb 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RISK
open
GitHub PoC94
CVE-2024-21893: SSRF Vulnerability in Ivanti Connect Secure
CVE-2024-21893HIGHunder attackransomware02 Feb 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RISK
open
GitHub PoC
Trinadh465/external_zlib_android-6.0.1_r22_CVE-2022-37434
CVE-2022-37434CRITICAL02 Feb 2024
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header
53RISK
open
GitHub PoC
Trinadh465/external_zlib_CVE-2022-37434
CVE-2022-37434CRITICAL02 Feb 2024
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header
53RISK
open
GitHub PoC
CVE-2023-22527 Batch scanning
CVE-2023-22527CRITICALunder attackransomware02 Feb 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
GitHub PoC1
PoC for Jenkins CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware01 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
previouspage 242 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.