Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
77,025 exploits
GitHub PoC
FlojBoj/CVE-2024-32002
CVE-2024-32002CRITICAL30 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL30 Jul 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
Just small script to exploit CVE-2024-32002
CVE-2024-32002CRITICAL30 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC3
PoC of CVE-2024-32002 - Remote Code Execution while cloning special-crafted local repositories
CVE-2024-32002CRITICAL30 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC86
GeoServer Remote Code Execution
CVE-2024-36401CRITICALunder attack30 Jul 2024
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
GIT RCE CVE-2024-32002
CVE-2024-32002CRITICAL29 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH29 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC2
PoC for CVE-2024-34144
CVE-2024-34144CRITICAL29 Jul 2024
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_
60RISK
open
GitHub PoC
Blind SQL Injection to RCE in a PHP open source application
CVE-2024-40498CRITICAL29 Jul 2024
SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbit
48RISK
open
GitHub PoC1
CVE-2024-39700 Proof of Concept
CVE-2024-39700CRITICAL29 Jul 2024
Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
48RISK
open
GitHub PoC80
Windows AppLocker Driver (appid.sys) LPE
CVE-2024-21338HIGHunder attackransomware29 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
CVE-2023-4220 POC RCE
CVE-2023-4220HIGH29 Jul 2024
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC
projectforsix/CVE-2021-45428-Defacer
CVE-2021-4542829 Jul 2024
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware29 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC2
veritas-rt/CVE-2010-0219
CVE-2010-021928 Jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
GitHub PoC
This repository contains scripts and resources for exploiting the Follina CVE and CVE-2021-40444 vulnerabilities in Microsoft Office. The scripts generate malicious document files that can execute arbitrary code on the target system.
CVE-2021-40444HIGHunder attackransomware28 Jul 2024
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware28 Jul 2024
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
A Reverse shell generator for gitlab-shell vulnerability cve 2024-32002
CVE-2024-32002CRITICAL28 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware28 Jul 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-5217CRITICALunder attack28 Jul 2024
Incomplete Input Validation in GlideExpression Script
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack28 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2010-021928 Jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
GitHub PoC5
CVE-2024-4879 & CVE-2024-5217 ServiceNow RCE Scanning Using Nuclei & Shodan Dork to find it.
CVE-2024-4879CRITICALunder attack28 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC2
vvts-alpha/CVE-2010-0219
CVE-2010-021928 Jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
GitHub PoC
CVE-2024-23897 exploit script
CVE-2024-23897CRITICALunder attackransomware28 Jul 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
local
CVE-2024-30088HIGHunder attackransomware27 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC2
Questa repository contiene una replica (tentativo di replica) scritto in Python per CVE-2024-30088.
CVE-2024-30088HIGHunder attackransomware27 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
CERTologists/HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892
CVE-2023-41892CRITICAL27 Jul 2024
Craft CMS Remote Code Execution vulnerability
85RISK
open
GitHub PoC
blackninja23/CVE-2024-32002
CVE-2024-32002CRITICAL27 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Jutrm/cve-2024-24919
CVE-2024-24919HIGHunder attackransomware26 Jul 2024
Information disclosure
100RISK
open
previouspage 369 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.