Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,542cataloged exploits
34,971CVEs with public exploitation
24,695lab-tested
76,313 exploits
VulnCheck XDB
initial-access
CVE-2019-023231 Jan 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC
asepsaepdin/CVE-2022-33891
CVE-2022-33891HIGHunder attack30 Jan 2025
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-0235MEDIUM30 Jan 2025
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RISK
open
GitHub PoC
asepsaepdin/CVE-2022-36804
CVE-2022-36804HIGHunder attack30 Jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware30 Jan 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware30 Jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC6
Proof of Concept for CVE-2022-45460
CVE-2022-45460CRITICAL30 Jan 2025
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack30 Jan 2025
Openfire administration console authentication bypass
100RISK
open
Metasploit600
Unauthenticated RCE in NetAlertX
CVE-2024-46506CRITICAL30 Jan 2025
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RISK
open
GitHub PoC
lukwagoasuman/-home-lukewago-Downloads-CVE-2021-23017-Nginx-1.14
CVE-2021-2301730 Jan 2025
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISK
open
GitHub PoC50
An XNU kernel race condition bug
CVE-2025-24118CRITICAL30 Jan 2025
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS S
48RISK
open
GitHub PoC1
## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands on a website running <b>Laravel <= v8.4.2</b>, that has "APP_DEBUG" set to "true" in its ".env" file.
CVE-2021-3129CRITICALunder attackransomware30 Jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
asepsaepdin/CVE-2023-32315
CVE-2023-32315HIGHunder attack30 Jan 2025
Openfire administration console authentication bypass
100RISK
open
GitHub PoC15
CVE-2024-8381: A SpiderMonkey Interpreter Type Confusion Bug.
CVE-2024-8381CRITICAL30 Jan 2025
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t
48RISK
open
Metasploit300
NetAlertX File Read Vulnerability
CVE-2024-48766HIGH30 Jan 2025
NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and
48RISK
open
VulnCheck XDB
initial-access
CVE-2022-33891HIGHunder attack30 Jan 2025
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
GitHub PoC4
honeyb33z/cve-2020-11023-scanner
CVE-2020-11023MEDIUMunder attack30 Jan 2025
Potential XSS vulnerability in jQuery
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHunder attack30 Jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC
asepsaepdin/CVE-2021-42013
CVE-2021-42013CRITICALunder attackransomware30 Jan 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALunder attackransomware29 Jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-55591CRITICALunder attackransomware29 Jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
GitHub PoC1
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.
CVE-2024-12084CRITICAL29 Jan 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-11972CRITICAL29 Jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open
GitHub PoC
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
CVE-2024-11972CRITICAL29 Jan 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open
GitHub PoC11
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in certain Fortinet devices.
CVE-2024-55591CRITICALunder attackransomware29 Jan 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
GitHub PoC1
bsec404/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware29 Jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALunder attackransomware29 Jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALunder attackransomware29 Jan 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC2
Ivanti Connect Secure, Policy Secure & ZTA Gateways - CVE-2025-0282
CVE-2025-0282CRITICALunder attackransomware28 Jan 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-48248HIGHunder attack28 Jan 2025
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RISK
open
previouspage 311 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.