Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,175GitHub PoC 14,096VulnCheck XDB 8,607Nuclei 4,255Metasploit 3,474✓ verified onlyrecentpopularrisk
77,020 exploits
GitHub PoC
elliotosama/CVE-2012-2982
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open ↗GitHub PoC★ 223
RDL的堆溢出导致的RCE
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 9
SecStarBot/CVE-2024-38077-POC
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 5
it is script designed to interact with a router by sending a payload to its system tools. The script retrieves the router's configuration from environment variables to ensure security. It includes functions for generating an authorization header, sending a payload, and logging the process.
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
53RISK
open ↗GitHub PoC★ 1
An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or cannot apply the official patch, try this one.
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC★ 1
CVE-2024-41651
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func
48RISK
open ↗GitHub PoC
bolkv/CVE-2024-4320
Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
60RISK
open ↗GitHub PoC★ 2
exploit que vulnera Jenkins hecho en Python
ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
48RISK
open ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗GitHub PoC★ 49
Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗Metasploit500
Asterisk AMI Originate Authenticated RCE
Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
36RISK
open ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗Metasploit300
Camaleon CMS Directory Traversal CVE-2024-46987
Arbitrary path traversal in Camaleon CMS
61RISK
open ↗VulnCheck XDB
initial-access
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC
This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack. It provides information on the vulnerable code, recommended fixes, and how to extract and decrypt administrative credentials.
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
48RISK
open ↗GitHub PoC★ 6
CVE-2024-32113 Apache OFBIZ Batch Scanning
Apache OFBiz: Path traversal leading to RCE
100RISK
open ↗GitHub PoC
VanishedPeople/CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC★ 1
Found this on exploit-db, decided to make my own for practice. This exploit will search out the passwd file and print the contents on a vulnerable system.
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISK
open ↗GitHub PoC★ 1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISK
open ↗GitHub PoC★ 6
Calibre 远程代码执行(CVE-2024-6782)Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
Calibre Remote Code Execution
85RISK
open ↗GitHub PoC★ 1
This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗GitHub PoC★ 1
CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗VulnCheck XDB
initial-access
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open ↗Metasploit300
Ivanti Virtual Traffic Manager Authentication Bypass (CVE-2024-7593)
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
100RISK
open ↗VulnCheck XDB
local
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RISK
open ↗Exploit-DB
Devika v1 - Path Traversal via 'snapshot_path'
The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr
68RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.