Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
76,496 exploits
GitHub PoC1
Copy of the POC for CVE-2023-1545
CVE-2023-1545HIGH24 Feb 2025
SQL Injection in nilsteampassnet/teampass
41RISK
open
GitHub PoC4
numanturle/CVE-2025-25279
CVE-2025-25279CRITICAL24 Feb 2025
Arbitrary file read in Mattermost Boards via import & export board archive
53RISK
open
VulnCheck XDB
initial-access
CVE-2023-21839HIGHunder attack24 Feb 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open
GitHub PoC3
shishirghimir/CVE-2024-53677-Exploit
CVE-2024-53677CRITICAL24 Feb 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC
vivigotnotime/CVE-2023-22515-Exploit-Script
CVE-2023-22515CRITICALunder attackransomware24 Feb 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack24 Feb 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
Code to exploit CVE-2021-4034
CVE-2021-4034HIGHunder attack24 Feb 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware24 Feb 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
CVE-2013-3900MEDIUMunder attack23 Feb 2025
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
CVE-2025-0411HIGHunder attack23 Feb 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open
VulnCheck XDB
local
CVE-2025-0411HIGHunder attack23 Feb 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open
GitHub PoC1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
CVE-2024-10924CRITICAL23 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL23 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
Example usage: exploit.sh http://site.com
CVE-2023-1545HIGH22 Feb 2025
SQL Injection in nilsteampassnet/teampass
41RISK
open
GitHub PoC4
CVE-2023-1698 Proof of Concept (PoC)
CVE-2023-1698CRITICAL21 Feb 2025
WAGO: WBM Command Injection in multiple products
85RISK
open
GitHub PoC1
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALunder attack21 Feb 2025
Remote code execution in Wazuh server
100RISK
open
GitHub PoC1
funixone/CVE-2024-24919---Exploit-Script
CVE-2024-24919HIGHunder attackransomware21 Feb 2025
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL21 Feb 2025
WAGO: WBM Command Injection in multiple products
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware21 Feb 2025
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH20 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
GitHub PoC2
PoC of the vulnerability CVE-2024-23346
CVE-2024-23346CRITICAL20 Feb 2025
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open
GitHub PoC
CVE-2025-24971 exploit
CVE-2025-24971CRITICAL20 Feb 2025
OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop
48RISK
open
GitHub PoC
anu
CVE-2024-1651CRITICAL20 Feb 2025
Torrentpier 2.4.1 - RCE
60RISK
open
GitHub PoC5
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
CVE-2025-24016CRITICALunder attack20 Feb 2025
Remote code execution in Wazuh server
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALunder attack20 Feb 2025
Remote code execution in Wazuh server
100RISK
open
Metasploit600
Remote Code Execution Vulnerability in XWiki Platform (CVE-2025-24893)
CVE-2025-24893CRITICALunder attack20 Feb 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack19 Feb 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
Metasploit600
SPIP Saisies Plugin Unauthenticated RCE
CVE-2025-71243CRITICAL19 Feb 2025
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack19 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack19 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
previouspage 308 / 2,550next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.