Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
77,020 exploits
Metasploit300
WordPress LearnPress Unauthenticated SQLi (CVE-2024-8522, CVE-2024-8529)
LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
75RISK
open ↗GitHub PoC★ 2
Spring Cloud Remote Code Execution
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISK
open ↗GitHub PoC★ 1
Powershell script that checks for cert padding in the Windows Registry and adds it if it does not exist. Meant to resolve the WinTrustVerify Vulnerability.
WinVerifyTrust Signature Validation Vulnerability
75RISK
open ↗GitHub PoC
OtisSymbos/CVE-2021-44228-Log4Shell-
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC
Log4J exploit CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 1
KaoXx/CVE-2022-37706
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open ↗GitHub PoC★ 1
Scanning CVE-2024-4577 vulnerability with a url list.
Argument Injection in PHP-CGI
100RISK
open ↗GitHub PoC★ 1
CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗VulnCheck XDB
client-side
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open ↗GitHub PoC
carradolly/CVE-2015-8660
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISK
open ↗GitHub PoC★ 3
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
48RISK
open ↗Metasploit600
VICIdial Authenticated Remote Code Execution
VICIdial Authenticated Remote Code Execution
58RISK
open ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open ↗GitHub PoC★ 5
CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open ↗GitHub PoC★ 9
0xRoqeeb/sqlpad-rce-exploit-CVE-2022-0944
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open ↗GitHub PoC
Python3 toolkit update
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open ↗GitHub PoC★ 1
Artemisxxx37/OverlayFS-PrivEsc-CVE-2022-0944
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open ↗Metasploit300
Vicidial SQL Injection Time-based Admin Credentials Enumeration
VICIdial Unauthenticated SQL Injection
85RISK
open ↗GitHub PoC★ 3
Analysis , Demo exploit and poc about CVE-2024-37084
CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
60RISK
open ↗GitHub PoC★ 5
SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open ↗GitHub PoC
PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: https://huntr.com/bounties/46630727-d923-4444-a421-537ecd63e7fb
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open ↗GitHub PoC★ 1
CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open ↗GitHub PoC★ 4
CVE-2018-0834 full code exec
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RISK
open ↗GitHub PoC
CVE-2024-23897 분석
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗VulnCheck XDB
initial-access
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open ↗GitHub PoC★ 7
A proof of concept exploit for SQLPad RCE (CVE-2022-0944).
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.