Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,012cataloged exploits
35,274CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,072VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
76,607 exploits
VulnCheck XDB
remote-with-credentials
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open ↗GitHub PoC★ 1
CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open ↗GitHub PoC
0-Gram/CVE-2022-41040
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 1
CVE-2024-32002 是 Git 中的一个严重漏洞,允许攻击者在用户执行 git clone 操作时远程执行任意代码(RCE)。
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC★ 1
BohemianHacks/CVE-2024-21534-poc
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RISK
open ↗GitHub PoC★ 24
CVE-2024-35250 的 Beacon Object File (BOF) 实现。
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗VulnCheck XDB
initial-access
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open ↗VulnCheck XDB
initial-access
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗VulnCheck XDB
initial-access
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗GitHub PoC
Broken Authentication in Wordpress plugin (Wawp Plugin < 3.0.18)
WordPress Wawp plugin < 3.0.18 - Account Takeover vulnerability
48RISK
open ↗VulnCheck XDB
remote-with-credentials
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open ↗VulnCheck XDB
denial-of-service
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RISK
open ↗VulnCheck XDB
initial-access
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗VulnCheck XDB
initial-access
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗VulnCheck XDB
initial-access
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗GitHub PoC
My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RISK
open ↗GitHub PoC
punitdarji/Paloalto-CVE-2024-0012
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗GitHub PoC
CVE-2024-0012是Palo Alto Networks PAN-OS软件中的一个身份验证绕过漏洞。该漏洞允许未经身份验证的攻击者通过网络访问管理Web界面,获取PAN-OS管理员权限,从而执行管理操作、篡改配置,或利用其他需要身份验证的特权提升漏洞(如CVE-2024-9474)
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗GitHub PoC★ 2
CVE-2024-0012批量检测脚本
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗Metasploit600
Pandora FMS authenticated command injection leading to RCE via LDAP using default DB password
Command Injection leading to RCE via LDAP Misconfiguration
50RISK
open ↗Metasploit600
mySCADA myPRO Manager Unauthenticated Command Injection (CVE-2024-47407)
mySCADA myPRO OS Command Injection
55RISK
open ↗GitHub PoC★ 2
This tool scans WordPress websites for vulnerabilities in the WP Time Capsule plugin related to CVE-2024-8856. It identifies plugin versions below 1.22.22 as vulnerable and logs results to vuln.txt. Simple and efficient, it helps security researchers and admins detect and address risks quickly.
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.