Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
77,020 exploits
Metasploit600
GiveWP Unauthenticated Donation Process Exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open ↗Metasploit600
GiveWP Unauthenticated Donation Process Exploit
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISK
open ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open ↗GitHub PoC★ 1
Python exploit for Chamilo Unrestricted File Upload Vuln - CVE-2023-4220
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗VulnCheck XDB
initial-access
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open ↗GitHub PoC
TeamCity CVE-2023-42793 RCE (Remote Code Execution)
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC★ 695
poc for CVE-2024-38063 (RCE in tcpip.sys)
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
CVE-2023-4220 PoC Chamilo RCE
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗GitHub PoC★ 24
LiteSpeed Cache Privilege Escalation PoC
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
75RISK
open ↗GitHub PoC★ 3
Telerik Report Server deserialization and authentication bypass exploit chain for CVE-2024-4358/CVE-2024-1800
Registration Authentication Bypass Vulnerability
100RISK
open ↗GitHub PoC★ 4
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open ↗Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
Traccar's unrestricted file upload vulnerability in device image upload could lead to remote code execution
48RISK
open ↗Metasploit600
Traccar v5 Remote Code Execution (CVE-2024-31214 and CVE-2024-24809)
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48RISK
open ↗GitHub PoC★ 19
Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)
Moodle: remote code execution via calculated question types
78RISK
open ↗GitHub PoC★ 2
Windows远程桌面授权服务CVE-2024-38077检测工具
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 2
CVE-2024-38063 research so you don't have to.
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗GitHub PoC
Research
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open ↗Metasploit300
SolarWinds Web Help Desk Backdoor (CVE-2024-28987)
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open ↗GitHub PoC★ 9
CVE-2024-38856 Exploit
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗VulnCheck XDB
remote-with-credentials
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISK
open ↗GitHub PoC★ 3
Proof-of-Concept for CVE-2024-5932 GiveWP PHP Object Injection
GiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
68RISK
open ↗VulnCheck XDB
infoleak
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open ↗GitHub PoC★ 1
CVE-2023-7028 POC && Exploit
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.