Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
77,020 exploits
VulnCheck XDB
infoleak
CVE-2024-5932CRITICAL21 Aug 2024
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
GitHub PoC
exr viewer
CVE-2023-50245CRITICAL21 Aug 2024
OpenEXR-viewer memory overflow vulnerability
48RISK
open
VulnCheck XDB
local
CVE-2022-3699HIGH21 Aug 2024
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack21 Aug 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
GitHub PoC
CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin
CVE-2023-29384CRITICAL20 Aug 2024
WordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.0 is vulnerable to Arbitrary File Upload
48RISK
open
VulnCheck XDB
infoleak
CVE-2020-1938CRITICALunder attack20 Aug 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-7928MEDIUM20 Aug 2024
FastAdmin lang path traversal
53RISK
open
VulnCheck XDB
infoleak
CVE-2024-7928MEDIUM20 Aug 2024
FastAdmin lang path traversal
53RISK
open
GitHub PoC
Reproducing the following CVEs with dockerfile:CVE-2024-33644 CVE-2024-34370 CVE-2024-22120
CVE-2024-33644CRITICAL20 Aug 2024
WordPress Customify Site Library plugin <= 0.0.9 - Remote Code Execution (RCE) vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL20 Aug 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC25
PHP CGI Argument Injection (CVE-2024-4577) RCE
CVE-2024-4577CRITICALunder attackransomware20 Aug 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix
CVE-2024-38063CRITICAL20 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Unauthenticated Remote Code Execution – Bricks
CVE-2024-25600CRITICAL20 Aug 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
RedTeam-Rediron/CVE-2020-1938
CVE-2020-1938CRITICALunder attack20 Aug 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.
CVE-2024-6387HIGH20 Aug 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware20 Aug 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
jeyabalaji711/CVE-2024-42919
CVE-2024-42919CRITICAL19 Aug 2024
eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
48RISK
open
VulnCheck XDB
initial-access
CVE-2022-27925HIGHunder attackransomware19 Aug 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-21587CRITICALunder attackransomware19 Aug 2024
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open
GitHub PoC
dweger-scripts/CVE-2024-38063-Remediation
CVE-2024-38063CRITICAL19 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
adobe commerce
CVE-2024-34102CRITICALunder attack19 Aug 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC
PoC
CVE-2022-27925HIGHunder attackransomware19 Aug 2024
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISK
open
GitHub PoC
s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH
CVE-2024-6387HIGH19 Aug 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
anmolksachan/CVE-2020-2733
CVE-2020-2733CRITICAL19 Aug 2024
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics)
68RISK
open
GitHub PoC1
Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15
CVE-2024-38856HIGHunder attack18 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC16
p0in7s/CVE-2024-38475
CVE-2024-38475CRITICALunder attack18 Aug 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
GitHub PoC
CVE-2024-7094 Vulnerability checker
CVE-2024-7094CRITICAL18 Aug 2024
JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution
60RISK
open
GitHub PoC
WTN-arny/CVE-2024-37085
CVE-2024-37085MEDIUMunder attackransomware18 Aug 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) per
68RISK
open
GitHub PoC
Poc for cve-2024-38063
CVE-2024-38063CRITICAL18 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Chamilo LMS Unauthenticated Big Upload File that allows remote code execution
CVE-2023-4220HIGH18 Aug 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
previouspage 364 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.