Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,647 exploits
VulnCheck XDB
client-side
CVE-2023-4762HIGHunder attack21 Oct 2024
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a
83RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-16651HIGHunder attack21 Oct 2024
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware21 Oct 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2015-7450CRITICALunder attack21 Oct 2024
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9805HIGHunder attack21 Oct 2024
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack21 Oct 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-48914CRITICAL21 Oct 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
75RISK
open
GitHub PoC39
Grafana RCE exploit (CVE-2024-9264)
CVE-2024-9264CRITICAL21 Oct 2024
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC
punitdarji/Grafana-CVE-2024-9264
CVE-2024-9264CRITICAL21 Oct 2024
Grafana SQL Expressions allow for remote code execution
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-23113CRITICALunder attack21 Oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM21 Oct 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC11
p33d/CVE-2024-23113
CVE-2024-23113CRITICALunder attack21 Oct 2024
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack21 Oct 2024
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
GitHub PoC5
Proof-of-Concept for LFI/Path Traversal vulnerability in Aiohttp =< 3.9.1
CVE-2024-23334MEDIUM20 Oct 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM20 Oct 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC7
File Read Proof of Concept for CVE-2024-9264
CVE-2024-9264CRITICAL20 Oct 2024
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC1
Affected versions of this package are vulnerable to Race Condition. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code remotely.
CVE-2021-32708CRITICAL19 Oct 2024
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
48RISK
open
GitHub PoC132
Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)
CVE-2024-9264CRITICAL19 Oct 2024
Grafana SQL Expressions allow for remote code execution
85RISK
open
Metasploit300
OneDev Unauthenticated Arbitrary File Read
CVE-2024-45309HIGH19 Oct 2024
OneDev vulnerable to arbitrary file reading for unauthenticated user
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-9593HIGH18 Oct 2024
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
61RISK
open
GitHub PoC11
Pre-Authentication Heap Overflow in Xlight SFTP server <= 3.9.4.2
CVE-2024-46483CRITICAL18 Oct 2024
Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which c
48RISK
open
GitHub PoC2
Security Bulletin for CVE-2024-35133 - With PoC
CVE-2024-35133MEDIUM18 Oct 2024
IBM Security Verify Access HTTP open redirect
33RISK
open
GitHub PoC
Vulnerability Overview CVE-2023-38408 affects OpenSSH versions < 9.3p2 and stems from improper validation of data when SSH agent forwarding is enabled. When users connect to a remote server with ssh -A, they allow the agent on their local machine to be used for authentication to further systems
CVE-2023-38408CRITICAL17 Oct 2024
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC11
tdonaworth/Firefox-CVE-2024-9680
CVE-2024-9680CRITICALunder attackransomware17 Oct 2024
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
83RISK
open
GitHub PoC2
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
CVE-2024-9234CRITICAL17 Oct 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM17 Oct 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-9234CRITICAL17 Oct 2024
GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
68RISK
open
VulnCheck XDB
local
CVE-2024-30090HIGH17 Oct 2024
Microsoft Streaming Service Elevation of Privilege Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2021-40539CRITICALunder attackransomware16 Oct 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
GitHub PoC
cuanh2333/CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware16 Oct 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
previouspage 345 / 2,555next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.