Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,060cataloged exploits
35,302CVEs with public exploitation
24,695lab-tested
77,051 exploits
GitHub PoC80
Windows AppLocker Driver (appid.sys) LPE
CVE-2024-21338HIGHunder attackransomware29 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC5
CVE-2024-4879 & CVE-2024-5217 ServiceNow RCE Scanning Using Nuclei & Shodan Dork to find it.
CVE-2024-4879CRITICALunder attack28 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC2
veritas-rt/CVE-2010-0219
CVE-2010-021928 Jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
GitHub PoC
This repository contains scripts and resources for exploiting the Follina CVE and CVE-2021-40444 vulnerabilities in Microsoft Office. The scripts generate malicious document files that can execute arbitrary code on the target system.
CVE-2021-40444HIGHunder attackransomware28 Jul 2024
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
A Reverse shell generator for gitlab-shell vulnerability cve 2024-32002
CVE-2024-32002CRITICAL28 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2010-021928 Jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
GitHub PoC2
vvts-alpha/CVE-2010-0219
CVE-2010-021928 Jul 2024
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RISK
open
GitHub PoC
CVE-2024-23897 exploit script
CVE-2024-23897CRITICALunder attackransomware28 Jul 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4879CRITICALunder attack28 Jul 2024
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
VulnCheck XDB
client-side
CVE-2021-40444HIGHunder attackransomware28 Jul 2024
Microsoft MSHTML Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-5217CRITICALunder attack28 Jul 2024
Incomplete Input Validation in GlideExpression Script
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware28 Jul 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
local
CVE-2024-30088HIGHunder attackransomware27 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC2
Questa repository contiene una replica (tentativo di replica) scritto in Python per CVE-2024-30088.
CVE-2024-30088HIGHunder attackransomware27 Jul 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
CERTologists/HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892
CVE-2023-41892CRITICAL27 Jul 2024
Craft CMS Remote Code Execution vulnerability
85RISK
open
GitHub PoC
blackninja23/CVE-2024-32002
CVE-2024-32002CRITICAL27 Jul 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Jutrm/cve-2024-24919
CVE-2024-24919HIGHunder attackransomware26 Jul 2024
Information disclosure
100RISK
open
GitHub PoC
PauloParoPP/CVE-2024-41110-SCAN
CVE-2024-41110CRITICAL26 Jul 2024
Moby authz zero length regression
53RISK
open
GitHub PoC
CVE-2021-44228 vulnerability study
CVE-2021-44228CRITICALunder attackransomware26 Jul 2024
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
Metasploit600
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
CVE-2024-2961HIGH26 Jul 2024
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
Metasploit600
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
CVE-2024-34102CRITICALunder attack26 Jul 2024
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC1
AndreaF17/PoC-CVE-2024-44349
CVE-2024-44349CRITICAL26 Jul 2024
A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute ar
63RISK
open
GitHub PoC
Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.
CVE-2023-7028CRITICALunder attack25 Jul 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack25 Jul 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
GitHub PoC6
vvpoglazov/cve-2024-41110-checker
CVE-2024-41110CRITICAL25 Jul 2024
Moby authz zero length regression
53RISK
open
GitHub PoC2
prelearn-code/CVE-2024-6387
CVE-2024-6387HIGH25 Jul 2024
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
a-roshbaik/CVE-2024-4577-PHP-RCE
CVE-2024-4577CRITICALunder attackransomware24 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4577CRITICALunder attackransomware24 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
a-roshbaik/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware24 Jul 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
ps4 cve-2008-3531
CVE-2008-353124 Jul 2024
Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled,
23RISK
open
previouspage 370 / 2,569next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.