Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
77,020 exploits
GitHub PoC★ 4
A proof of concept of the LFI vulnerability on aiohttp 3.9.1
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open ↗GitHub PoC★ 7
A proof of concept exploit for SQLPad RCE (CVE-2022-0944).
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open ↗GitHub PoC
quick powershell script to fix cve-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗VulnCheck XDB
initial-access
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RISK
open ↗GitHub PoC★ 5
🔥 CVE-2024-44849 Exploit
Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
75RISK
open ↗GitHub PoC
nteract 0.28.0 open redirect to RCE exploit
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
48RISK
open ↗GitHub PoC
deskfiler 1.2.3 Open Redirect exploit
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
48RISK
open ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open ↗Metasploit600
SPIP BigUp Plugin Unauthenticated RCE
SPIP Bigup Multipart File Upload OS Command Injection
85RISK
open ↗GitHub PoC★ 16
SPIP BigUp Plugin Unauthenticated RCE
SPIP Bigup Multipart File Upload OS Command Injection
85RISK
open ↗GitHub PoC★ 2
XSS to RCE in RenderTune v1.1.4 exploit
Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML
48RISK
open ↗GitHub PoC★ 16
CVE-2024-44000 is a vulnerability in the LiteSpeed Cache plugin, a popular WordPress plugin. This vulnerability affects session management in LiteSpeed Cache, allowing attackers to gain unauthorized access to sensitive data.
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open ↗GitHub PoC
LiteSpeed Unauthorized Account Takeover
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open ↗VulnCheck XDB
local
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open ↗GitHub PoC
test POC for CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open ↗VulnCheck XDB
initial-access
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISK
open ↗VulnCheck XDB
initial-access
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RISK
open ↗GitHub PoC
bryanqb07/CVE-2023-32315
Openfire administration console authentication bypass
100RISK
open ↗GitHub PoC★ 12
Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open ↗GitHub PoC★ 5
Research and PoC for CVE-2024-6386
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
53RISK
open ↗GitHub PoC★ 6
fru1ts/CVE-2024-44902
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
48RISK
open ↗GitHub PoC★ 1
This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗Metasploit600
Wordpress LiteSpeed Cache plugin cookie theft
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open ↗GitHub PoC★ 4
Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC★ 1
Adobe ColdFusion CVE-2023-26360/CVE-2023-29298 自动化实现反弹
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open ↗GitHub PoC★ 1
brownpanda29/Cve-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 1
(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.