Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
76,542 exploits
GitHub PoC1
The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
CVE-2021-2301708 Dec 2024
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware08 Dec 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server
CVE-2017-5638CRITICALunder attackransomware08 Dec 2024
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC4
D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins
CVE-2024-23897CRITICALunder attackransomware08 Dec 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC3
POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method
CVE-2024-42327CRITICAL07 Dec 2024
SQL injection in user.get API
70RISK
open
GitHub PoC
Calibre Remote Code Execution
CVE-2024-6782CRITICAL07 Dec 2024
Calibre Remote Code Execution
85RISK
open
GitHub PoC
Technical Details and Exploit for CVE-2024-11392
CVE-2024-11392HIGH07 Dec 2024
Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-6782CRITICAL07 Dec 2024
Calibre Remote Code Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL06 Dec 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-9465CRITICALunder attack06 Dec 2024
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
100RISK
open
GitHub PoC
lu4m575/CVE-2024-35286_scan.nse
CVE-2024-35286CRITICAL06 Dec 2024
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond
75RISK
open
GitHub PoC4
CVE-2024-10914 D-Link Remote Code Execution (RCE)
CVE-2024-10914CRITICAL06 Dec 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
fredagsguf/Windows-CVE-2024-38063
CVE-2024-38063CRITICAL06 Dec 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC3
depers-rus/CVE-2024-42327
CVE-2024-42327CRITICAL06 Dec 2024
SQL injection in user.get API
70RISK
open
GitHub PoC19
watchtowrlabs/Mitel-MiCollab-Auth-Bypass_CVE-2024-41713
CVE-2024-41713CRITICALunder attackransomware05 Dec 2024
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISK
open
GitHub PoC
Veeam Service Provider Console (VSPC) remote code execution.
CVE-2024-42448CRITICAL05 Dec 2024
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos
53RISK
open
GitHub PoC
PoC for Watchguard CVE-2022-26318 updated to Python3.12
CVE-2022-26318CRITICALunder attack05 Dec 2024
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISK
open
GitHub PoC1
Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en Chamilo LMS en versiones <= 1.11.24 permite a atacantes no autenticados realizar ataques de Cross Site Scripting almacenados y obtener código remoto ejecución mediante la carga de web shell.
CVE-2023-4220HIGH05 Dec 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack05 Dec 2024
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-41713CRITICALunder attackransomware05 Dec 2024
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26318CRITICALunder attack05 Dec 2024
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH05 Dec 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676304 Dec 2024
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-11680CRITICALunder attack04 Dec 2024
ProjectSend Unauthenticated Configuration Modification
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH04 Dec 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
infoleak
CVE-2022-138604 Dec 2024
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack04 Dec 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2023-32784HIGH04 Dec 2024
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a work
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-50498CRITICAL04 Dec 2024
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open
GitHub PoC12
This repository contains a Proof of Concept (PoC) exploit for CVE-2024-11680, a critical vulnerability in ProjectSend r1605 and older versions. The exploit targets an improper authentication flaw due Privilege Misconfiguration issues.
CVE-2024-11680CRITICALunder attack04 Dec 2024
ProjectSend Unauthenticated Configuration Modification
100RISK
open
previouspage 327 / 2,552next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.