Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,012cataloged exploits
35,274CVEs with public exploitation
24,695lab-tested
76,607 exploits
VulnCheck XDB
remote-with-credentials
CVE-2023-20198CRITICALunder attack23 Nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC1
CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。
CVE-2023-20198CRITICALunder attack23 Nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC
0-Gram/CVE-2022-41040
CVE-2022-41040HIGHunder attackransomware23 Nov 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
CVE-2024-32002 是 Git 中的一个严重漏洞,允许攻击者在用户执行 git clone 操作时远程执行任意代码(RCE)。
CVE-2024-32002CRITICAL23 Nov 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC1
BohemianHacks/CVE-2024-21534-poc
CVE-2024-21534CRITICAL23 Nov 2024
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati
48RISK
open
GitHub PoC24
CVE-2024-35250 的 Beacon Object File (BOF) 实现。
CVE-2024-35250HIGHunder attack23 Nov 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack23 Nov 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attackransomware23 Nov 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-29442HIGH22 Nov 2024
Authentication bypass
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-47575CRITICALunder attack22 Nov 2024
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALunder attack22 Nov 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864622 Nov 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-25065MEDIUM22 Nov 2024
OpenNetAdmin os command injection
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack22 Nov 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack22 Nov 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
Broken Authentication in Wordpress plugin (Wawp Plugin < 3.0.18)
CVE-2024-52475CRITICAL22 Nov 2024
WordPress Wawp plugin < 3.0.18 - Account Takeover vulnerability
48RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-20198CRITICALunder attack22 Nov 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH22 Nov 2024
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
VulnCheck XDB
denial-of-service
CVE-2024-7965HIGHunder attack22 Nov 2024
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27130HIGH22 Nov 2024
QTS, QuTS hero
53RISK
open
GitHub PoC
My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection
CVE-2024-52433CRITICAL22 Nov 2024
WordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
63RISK
open
GitHub PoC
punitdarji/Paloalto-CVE-2024-0012
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC
CVE-2024-0012是Palo Alto Networks PAN-OS软件中的一个身份验证绕过漏洞。该漏洞允许未经身份验证的攻击者通过网络访问管理Web界面,获取PAN-OS管理员权限,从而执行管理操作、篡改配置,或利用其他需要身份验证的特权提升漏洞(如CVE-2024-9474)
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC2
CVE-2024-0012批量检测脚本
CVE-2024-0012CRITICALunder attackransomware22 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
Metasploit600
Pandora FMS authenticated command injection leading to RCE via LDAP using default DB password
CVE-2024-11320MEDIUM21 Nov 2024
Command Injection leading to RCE via LDAP Misconfiguration
50RISK
open
Metasploit600
mySCADA myPRO Manager Unauthenticated Command Injection (CVE-2024-47407)
CVE-2024-47407CRITICAL21 Nov 2024
mySCADA myPRO OS Command Injection
55RISK
open
GitHub PoC2
This tool scans WordPress websites for vulnerabilities in the WP Time Capsule plugin related to CVE-2024-8856. It identifies plugin versions below 1.22.22 as vulnerable and logs results to vuln.txt. Simple and efficient, it helps security researchers and admins detect and address risks quickly.
CVE-2024-8856CRITICAL21 Nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
previouspage 333 / 2,554next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.