Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,647 exploits
VulnCheck XDB
initial-access
CVE-2023-3722HIGH19 Nov 2024
Avaya Aura Device Services Remote Code Execution
56RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware19 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware19 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
GitHub PoC20
CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC
ubaydev/CVE-2024-10508
CVE-2024-10508CRITICAL19 Nov 2024
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
48RISK
open
VulnCheck XDB
local
CVE-2024-49039HIGHunder attackransomware19 Nov 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC24
watchtowrlabs/palo-alto-panos-cve-2024-0012
CVE-2024-0012CRITICALunder attackransomware19 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
Metasploit500
Ubuntu needrestart Privilege Escalation
CVE-2024-48990HIGH19 Nov 2024
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tric
41RISK
open
VulnCheck XDB
infoleak
CVE-2018-376019 Nov 2024
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
43RISK
open
GitHub PoC143
WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler
CVE-2024-49039HIGHunder attackransomware19 Nov 2024
Windows Task Scheduler Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC3
Unauthenticated Remote Code Execution via Angular-Base64-Upload Library (npm:bower)
CVE-2024-42640CRITICAL19 Nov 2024
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISK
open
VulnCheck XDB
initial-access
CVE-2017-12615HIGHunder attackransomware19 Nov 2024
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC19
Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).
CVE-2024-10924CRITICAL19 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
CVE-2024-3806CRITICAL18 Nov 2024
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RISK
open
GitHub PoC
Andriod binder bug record
CVE-2019-2215HIGHunder attack18 Nov 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
VulnCheck XDB
initial-access
CVE-2024-9593HIGH18 Nov 2024
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL18 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-3806CRITICAL18 Nov 2024
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
48RISK
open
Metasploit600
Palo Alto Networks PAN-OS Management Interface Unauthenticated Remote Code Execution
CVE-2024-0012CRITICALunder attackransomware18 Nov 2024
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
Metasploit600
Palo Alto Networks PAN-OS Management Interface Unauthenticated Remote Code Execution
CVE-2024-9474MEDIUMunder attackransomware18 Nov 2024
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
GitHub PoC8
WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it at your own risk!
CVE-2024-10924CRITICAL18 Nov 2024
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC2
Relais 2FA <= 1.0 - Authentication Bypass
CVE-2024-10245CRITICAL17 Nov 2024
Relais 2FA <= 1.0 - Authentication Bypass
48RISK
open
GitHub PoC2
Vuln disclosure for XOne app
CVE-2024-54820CRITICAL17 Nov 2024
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL16 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-1698CRITICAL16 Nov 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-8856CRITICAL16 Nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
GitHub PoC1
jesicatjan/WordPress-NotificationX-CVE-2024-1698
CVE-2024-1698CRITICAL16 Nov 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC9
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
CVE-2024-10914CRITICAL16 Nov 2024
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC3
PoC for Windows' IPv6 CVE-2024-38063
CVE-2024-38063CRITICAL16 Nov 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
WordPress WP Time Capsule Plugin Arbitrary File Upload Vulnerability
CVE-2024-8856CRITICAL16 Nov 2024
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
previouspage 336 / 2,555next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.