Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
77,020 exploits
GitHub PoC
CVE-2023-4220 Chamilo Exploit
CVE-2023-4220HIGH27 Aug 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC2
CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
CVE-2023-41425MEDIUM27 Aug 2024
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC4
Jelly Template Injection Vulnerability in ServiceNow | POC CVE-2024-4879
CVE-2024-4879CRITICALunder attack27 Aug 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC2
PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26
CVE-2024-25641CRITICAL27 Aug 2024
Cacti RCE vulnerability when importing packages
85RISK
open
GitHub PoC
zxybfq/CVE-2021-4034
CVE-2021-4034HIGHunder attack27 Aug 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack27 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack27 Aug 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-28000CRITICAL27 Aug 2024
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open
GitHub PoC1
Nuclei template to scan for Apache Ofbiz affecting versions before 18.12.15
CVE-2024-38856HIGHunder attack27 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC20
patchpoint/CVE-2024-38063
CVE-2024-38063CRITICAL27 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC10
CVE-2024-25641 - RCE Automated Exploit - Cacti 1.2.26
CVE-2024-25641CRITICAL27 Aug 2024
Cacti RCE vulnerability when importing packages
85RISK
open
Metasploit600
Moodle Remote Code Execution (CVE-2024-43425)
CVE-2024-43425HIGH27 Aug 2024
Moodle: remote code execution via calculated question types
78RISK
open
GitHub PoC8
This repository automates the process of exploiting CVE-2024-25641 on Cacti 1.2.26
CVE-2024-25641CRITICAL26 Aug 2024
Cacti RCE vulnerability when importing packages
85RISK
open
GitHub PoC
POC & Lab For CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware26 Aug 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Apache-HTTP-Server-2.4.50-RCE This tool is designed to test Apache servers for the CVE-2021-41773 / CVE-2021-42013 vulnerability. It is intended for educational purposes only and should be used responsibly on systems you have explicit permission to test.
CVE-2021-41773HIGHunder attackransomware26 Aug 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2024-45265
CVE-2024-45265CRITICAL26 Aug 2024
A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to exe
48RISK
open
GitHub PoC
sanan2004/CVE-2023-20198
CVE-2023-20198CRITICALunder attack26 Aug 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware26 Aug 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware26 Aug 2024
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
RCE OpenSSH CVE-2024-6387 Check and Exploit
CVE-2024-6387HIGH26 Aug 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
Sudo Privilege Escalation: CVE-2023-22809 Simulation This project simulates the Sudo privilege escalation vulnerability (CVE-2023-22809) to demonstrate how unauthorized root access can be gained. It involves identifying and exploiting this vulnerability in a controlled environment using Parrot OS, the Sudo command, and Bash scripting.
CVE-2023-22809HIGH26 Aug 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack26 Aug 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware26 Aug 2024
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH25 Aug 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALunder attack25 Aug 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-5932CRITICAL25 Aug 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
GitHub PoC2
Modified for GLPI Offsec Lab: call_user_func, array_map, passthru
CVE-2022-35914CRITICALunder attack25 Aug 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
GitHub PoC77
GiveWP PHP Object Injection exploit
CVE-2024-5932CRITICAL25 Aug 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
Metasploit600
GiveWP Unauthenticated Donation Process Exploit
CVE-2024-5932CRITICAL25 Aug 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
Metasploit600
GiveWP Unauthenticated Donation Process Exploit
CVE-2024-8353CRITICAL25 Aug 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISK
open
previouspage 362 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.