Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,647 exploits
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware16 Oct 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC2
ADSelfService Plus RCE漏洞 检测工具 (二开)
CVE-2021-40539CRITICALunder attackransomware16 Oct 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
GitHub PoC
Exploit and check CVE-2013-5211
CVE-2013-521116 Oct 2024
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISK
open
GitHub PoC43
CVE-2024-40711-exp
CVE-2024-40711CRITICALunder attackransomware16 Oct 2024
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-40539CRITICALunder attackransomware16 Oct 2024
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RISK
open
GitHub PoC
cuanh2333/CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware16 Oct 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware15 Oct 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC2
Guide and theoretical code for CVE-2023-35674
CVE-2023-35674HIGHunder attack15 Oct 2024
In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the cod
71RISK
open
GitHub PoC
idkwastaken/CVE-2023-32560
CVE-2023-32560HIGH15 Oct 2024
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disrup
78RISK
open
GitHub PoC
idkwastaken/CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware15 Oct 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC3
Vulnerability CVE-2024-38063
CVE-2024-38063CRITICAL15 Oct 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC5
ssst0n3/poc-cve-2024-0132
CVE-2024-0132CRITICAL15 Oct 2024
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RISK
open
VulnCheck XDB
client-side
CVE-2023-6000MEDIUM14 Oct 2024
Popup Builder < 4.2.3 - Unauthenticated Stored XSS
48RISK
open
GitHub PoC
idkwastaken/CVE-2024-38063
CVE-2024-38063CRITICAL14 Oct 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
shanglyu/CVE-2024-1698
CVE-2024-1698CRITICAL14 Oct 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC5
longhoangth18/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware14 Oct 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC9
PoC for the Untrusted Pointer Dereference in the ks.sys driver
CVE-2024-35250HIGHunder attack14 Oct 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware14 Oct 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
kkhackz0013/CVE-2024-36401
CVE-2024-36401CRITICALunder attack14 Oct 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack14 Oct 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
a proof of concept of the CVE-2024-27198 which infect jetbrains teamCity
CVE-2024-27198CRITICALunder attackransomware14 Oct 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-1698CRITICAL14 Oct 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware14 Oct 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1591613 Oct 2024
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system
23RISK
open
VulnCheck XDB
local
CVE-2024-35250HIGHunder attack13 Oct 2024
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
GitHub PoC
Gilospy/CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware13 Oct 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
lemonadern/poc-cve-2019-14287
CVE-2019-1428713 Oct 2024
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware13 Oct 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
PoC for RCE in SQLPad (CVE-2022-0944)
CVE-2022-0944CRITICAL13 Oct 2024
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC2
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
CVE-2024-8529CRITICAL12 Oct 2024
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
68RISK
open
previouspage 346 / 2,555next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.