Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
77,020 exploits
GitHub PoC1
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
CVE-2024-7854CRITICAL04 Oct 2024
Woo Inquiry <= 0.1 - Unauthenticated SQL Injection
63RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-53375HIGH04 Oct 2024
An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exi
53RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware04 Oct 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM03 Oct 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
local
CVE-2024-0582HIGH03 Oct 2024
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open
GitHub PoC2
Nortek Linear eMerge E3 Pre-Auth RCE PoC (CVE-2024-9441)
CVE-2024-9441CRITICAL03 Oct 2024
Linear eMerge e3-Series Forgot Password Command Injection
60RISK
open
GitHub PoC3
CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.
CVE-2023-41425MEDIUM02 Oct 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC5
This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The script uses Scapy to send various types of requests (ICMP, ARP, or TCP) and checks if the responses contain any padding data that could potentially leak sensitive memory contents.
CVE-2003-000101 Oct 2024
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISK
open
Exploit-DB
openSIS 9.1 - SQLi (Authenticated)
CVE-2024-46626HIGHwebappsphp01 Oct 2024
OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
41RISK
open
GitHub PoC1
Wechat Social login <= 1.3.0 - Authentication Bypass
CVE-2024-9106CRITICAL01 Oct 2024
Wechat Social login <= 1.3.0 - Authentication Bypass
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware30 Sep 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC12
GiveWP PHP Object Injection exploit
CVE-2024-8353CRITICAL30 Sep 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISK
open
GitHub PoC10
POC - Jenkins File Read Vulnerability - CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware30 Sep 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC8
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
CVE-2024-4040CRITICALunder attack30 Sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack30 Sep 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-8353CRITICAL30 Sep 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISK
open
GitHub PoC8
p33d/CVE-2024-43917
CVE-2024-43917CRITICAL29 Sep 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open
GitHub PoC10
CVE-2021-3129 (Laravel Ignition RCE Exploit)
CVE-2021-3129CRITICALunder attackransomware29 Sep 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware29 Sep 2024
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware29 Sep 2024
Information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-43917CRITICAL29 Sep 2024
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open
GitHub PoC6
PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing server responses
CVE-2024-24919HIGHunder attackransomware29 Sep 2024
Information disclosure
100RISK
open
GitHub PoC1
GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions
CVE-2024-36401CRITICALunder attack28 Sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC42
p33d/CVE-2024-45519
CVE-2024-45519CRITICALunder attack28 Sep 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-47176MEDIUM28 Sep 2024
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
infoleak
CVE-2024-38816HIGH28 Sep 2024
CVE-2024-38816: Path traversal vulnerability in functional web frameworks
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-45519CRITICALunder attack28 Sep 2024
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-29269HIGH28 Sep 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack28 Sep 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC1
ADManager Plus Build < 7210 Elevation of Privilege Vulnerability
CVE-2024-24409HIGH28 Sep 2024
Privilege Escalation
41RISK
open
previouspage 353 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.