Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
77,020 exploits
VulnCheck XDB
initial-access
CVE-2023-4220HIGH18 Aug 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
infoleak
CVE-2024-38475CRITICALunder attack18 Aug 2024
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack18 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC1
Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15
CVE-2024-38856HIGHunder attack18 Aug 2024
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware17 Aug 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Comodo
CVE-2018-1743117 Aug 2024
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RISK
open
GitHub PoC
POC
CVE-2024-32002CRITICAL17 Aug 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
CVE-2024-4577 Exploits
CVE-2024-4577CRITICALunder attackransomware17 Aug 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC87
Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.
CVE-2024-38063CRITICAL17 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-27198CRITICALunder attackransomware16 Aug 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
Metasploit600
SPIP Unauthenticated RCE via porte_plume Plugin
CVE-2024-7954CRITICAL16 Aug 2024
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC
PoC about CVE-2024-27198
CVE-2024-27198CRITICALunder attackransomware16 Aug 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC
1amthebest1/CVE-2023-27372
CVE-2023-27372CRITICAL15 Aug 2024
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC7
CVE-2024-38077,仅支持扫描测试~
CVE-2024-38077CRITICAL15 Aug 2024
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL15 Aug 2024
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC
MahdiOsman/CVE-2018-15473-SNMPv1-2-Community-String-Vulnerability-Testing
CVE-2018-15473MEDIUM15 Aug 2024
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC13
mitigation script by disabling ipv6 of all interfaces
CVE-2024-38063CRITICAL15 Aug 2024
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
CVE-2024-45256CRITICAL15 Aug 2024
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overw
43RISK
open
GitHub PoC1
An issue in Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
CVE-2024-42850CRITICAL15 Aug 2024
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity
48RISK
open
Metasploit600
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
CVE-2024-45257HIGH15 Aug 2024
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbi
36RISK
open
GitHub PoC3
This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where I could use gopher to make internal requests on Zabbix vulnerable to RCE.
CVE-2024-22120CRITICAL14 Aug 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISK
open
GitHub PoC125
fortra/CVE-2024-30051
CVE-2024-30051HIGHunder attackransomware14 Aug 2024
Windows DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
JolyIrsb/CVE-2024-4956
CVE-2024-4956HIGH14 Aug 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC
Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool is particularly useful for security researchers and penetration testers.
CVE-2024-4879CRITICALunder attack14 Aug 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
local
CVE-2024-30051HIGHunder attackransomware14 Aug 2024
Windows DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
local
CVE-2023-22809HIGH14 Aug 2024
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-22120CRITICAL14 Aug 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack14 Aug 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-22120CRITICAL13 Aug 2024
Time Based SQL Injection in Zabbix Server Audit Log
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-34102CRITICALunder attack13 Aug 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
previouspage 365 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.