Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,607 exploits
Metasploit600
Pandora FMS authenticated command injection leading to RCE via LDAP using default DB password
CVE-2024-11320MEDIUM21 Nov 2024
Command Injection leading to RCE via LDAP Misconfiguration
50RISK
open
GitHub PoC2
This tool scans WordPress websites for vulnerabilities in the WP Time Capsule plugin related to CVE-2024-8856. It identifies plugin versions below 1.22.22 as vulnerable and logs results to vuln.txt. Simple and efficient, it helps security researchers and admins detect and address risks quickly.
CVE-2024-8856CRITICAL21 Nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
Metasploit600
mySCADA myPRO Manager Unauthenticated Command Injection (CVE-2024-47407)
CVE-2024-47407CRITICAL21 Nov 2024
mySCADA myPRO OS Command Injection
55RISK
open
GitHub PoC
PoC for PAN-OS Exploit
CVE-2024-9474MEDIUMunder attackransomware20 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL20 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC1
PANW NGFW CVE-2024-0012
CVE-2024-0012CRITICALunder attackransomware20 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC3
Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164
CVE-2024-10924CRITICAL20 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware20 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware20 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
GitHub PoC
FAFAF
CVE-2018-15473MEDIUM20 Nov 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC
CVE-2024-52316 - Apache Tomcat Authentication Bypass Vulnerability
CVE-2024-52316CRITICAL20 Nov 2024
Apache Tomcat: Authentication bypass when using Jakarta Authentication API
48RISK
open
GitHub PoC
GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization
CVE-2024-6330CRITICAL20 Nov 2024
GEO my WordPress < 4.4.0.2 - Unauthenticated RCE via LFI
48RISK
open
GitHub PoC
POC for CVE-2024-10924 written in Python
CVE-2024-10924CRITICAL20 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
CVE-2023-28354
CVE-2023-28354CRITICAL20 Nov 2024
An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against aff
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware19 Nov 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC
ubaydev/CVE-2024-10508
CVE-2024-10508CRITICAL19 Nov 2024
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-3722HIGH19 Nov 2024
Avaya Aura Device Services Remote Code Execution
56RISK
open
GitHub PoC24
watchtowrlabs/palo-alto-panos-cve-2024-0012
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC20
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC
Simple Python script
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC19
Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC3
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library (npm:bower)
CVE-2024-42640CRITICAL19 Nov 2024
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISK
open
GitHub PoC45
PAN-OS auth bypass + RCE
CVE-2024-9474MEDIUMunder attackransomware19 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
Metasploit500
Ubuntu needrestart Privilege Escalation
CVE-2024-48990HIGH19 Nov 2024
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric
41RISK
open
VulnCheck XDB
infoleak
CVE-2018-376019 Nov 2024
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISK
open
VulnCheck XDB
local
CVE-2024-49039HIGHunder attackransomware19 Nov 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISK
open
previouspage 334 / 2,554next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.