Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
76,647 exploits
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware09 Oct 2024
Information disclosure
100RISK
open
GitHub PoC3
is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)
CVE-2024-27198CRITICALunder attackransomware09 Oct 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC
Apache CouchDB 3.2.1 - Remote Code Execution (RCE) Checker
CVE-2022-24706CRITICALunder attack08 Oct 2024
Remote Code Execution Vulnerability in Packaging
100RISK
open
GitHub PoC1
Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.
CVE-2021-44228CRITICALunder attackransomware08 Oct 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
TeamCity server scanner to detect CVE-2023-42793
CVE-2023-42793CRITICALunder attackransomware08 Oct 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attac
CVE-2024-1207CRITICAL08 Oct 2024
Booking Calendar <= 9.9 - Unauthenticated SQL Injection
48RISK
open
GitHub PoC1
Agilevatester/FlaskCache_CVE-2021-33026_POC
CVE-2021-33026CRITICAL08 Oct 2024
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e
48RISK
open
GitHub PoC
bka/magento-cve-2024-34102-exploit-cosmicstring
CVE-2024-34102CRITICALunder attack08 Oct 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC1
Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.
CVE-2024-38063CRITICAL08 Oct 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
wargame, CVE-2024-4367
CVE-2024-4367MEDIUM08 Oct 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
VulnCheck XDB
initial-access
CVE-2024-7029HIGH08 Oct 2024
Command Injection in AVTech AVM1203 (IP Camera)
68RISK
open
Metasploit600
Ivanti Connect Secure Authenticated Remote Code Execution via OpenSSL CRLF Injection
CVE-2024-37404CRITICAL08 Oct 2024
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Se
65RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware08 Oct 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-24706CRITICALunder attack08 Oct 2024
Remote Code Execution Vulnerability in Packaging
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-34102CRITICALunder attack08 Oct 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-45409CRITICAL07 Oct 2024
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
53RISK
open
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALunder attackransomware07 Oct 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM07 Oct 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM07 Oct 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
infoleak
CVE-2022-241407 Oct 2024
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-919307 Oct 2024
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-919307 Oct 2024
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALunder attack07 Oct 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC1
Automated Exploit for CVE-2020-6287
CVE-2020-6287CRITICALunder attack07 Oct 2024
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RISK
open
GitHub PoC83
Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
CVE-2024-45409CRITICAL07 Oct 2024
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
53RISK
open
GitHub PoC4
is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)
CVE-2019-919306 Oct 2024
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
GitHub PoC1
CVE-2023-22527 | RCE using SSTI in Confluence
CVE-2023-22527CRITICALunder attackransomware06 Oct 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-919306 Oct 2024
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALunder attackransomware06 Oct 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALunder attack06 Oct 2024
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
previouspage 348 / 2,555next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.