Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
76,107 exploits
GitHub PoC
Exploits Python cve-2019-9053– by HackHeart
CVE-2019-905315 Apr 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
Kiểm thử xâm nhập
CVE-2021-44228CRITICALunder attackransomware14 Apr 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Kiểm thử xâm nhập
CVE-2021-41773HIGHunder attackransomware14 Apr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution,
CVE-2021-42362HIGH14 Apr 2025
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISK
open
GitHub PoC
AsierEgana/cve-2021-4034
CVE-2021-4034HIGHunder attack14 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
OpenPanel 0.3.4 - Incorrect Access Control
CVE-2024-53582HIGHwebappsmultiple14 Apr 2025
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec
41RISK
open
Exploit-DB
Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
CVE-2019-19245webappsmultiple14 Apr 2025
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[use
23RISK
open
GitHub PoC
PoC for CVE-2023-27350
CVE-2023-27350CRITICALunder attackransomware14 Apr 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
Exploit-DB
GestioIP 3.5.7 - Remote Command Execution (RCE)
CVE-2024-48760CRITICALremotemultiple14 Apr 2025
An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke
75RISK
open
Metasploit600
Craft CMS Image Transform Preauth RCE (CVE-2025-32432)
CVE-2025-32432CRITICALunder attack14 Apr 2025
Craft CMS Allows Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH14 Apr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware14 Apr 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack14 Apr 2025
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack14 Apr 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
Exploit-DB
GestioIP 3.5.7 - Cross-Site Scripting (XSS)
CVE-2024-50857MEDIUMremotemultiple14 Apr 2025
The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en
48RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack14 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH14 Apr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL14 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Laboratorio técnico de ciberseguridad donde se realiza reconocimiento de red con Nmap y explotación de la vulnerabilidad CVE-2011-2523 (vsftpd 2.3.4) mediante Metasploit Framework. Proyecto académico orientado a demostrar habilidades en análisis de vulnerabilidades, uso de herramientas de pentesting y reporte técnico.
CVE-2011-252314 Apr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware14 Apr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware14 Apr 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
jakehomb/cve-2023-42793
CVE-2023-42793CRITICALunder attackransomware14 Apr 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
POC for CVE-2023-40028: Ghost CMS Arbitrary File Read
CVE-2023-40028MEDIUM14 Apr 2025
Arbitrary file read via symlinks in Ghost
45RISK
open
Exploit-DB
OpenPanel 0.3.4 - Directory Traversal
CVE-2024-53537CRITICALwebappsmultiple14 Apr 2025
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager
48RISK
open
Exploit-DB
Pimcore 11.4.2 - Stored cross site scripting
CVE-2024-11954MEDIUMwebappsmultiple14 Apr 2025
Pimcore Search Document cross site scripting
33RISK
open
Exploit-DB
OpenPanel Copy and View functions in the File Manager 0.3.4 - Directory Traversal
CVE-2024-53582HIGHwebappsmultiple14 Apr 2025
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec
41RISK
open
Exploit-DB
Pimcore customer-data-framework 4.2.0 - SQL injection
CVE-2024-11956MEDIUMwebappsmultiple14 Apr 2025
Pimcore customer-data-framework list sql injection
33RISK
open
GitHub PoC
pulentoski/Explotacion-CVE-2023-32315-Openfire
CVE-2023-32315HIGHunder attack14 Apr 2025
Openfire administration console authentication bypass
100RISK
open
GitHub PoC2
HTTP/2 Rapid Reset Exploit PoC
CVE-2023-44487HIGHunder attack14 Apr 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
Exploit-DB
GestioIP 3.5.7 - Stored Cross-Site Scripting (Stored XSS)
CVE-2024-50861MEDIUMremotemultiple14 Apr 2025
The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod
33RISK
open
previouspage 278 / 2,537next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.