Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
76,888 exploits
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware17 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Expolit for CVE-2024-23334 (aiohttp >= 1.0.5> && <=3.9.1)
CVE-2024-23334MEDIUM17 Jun 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC10
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
CVE-2024-4367MEDIUM17 Jun 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
WinRAR漏洞测试复现。详参:https://flowus.cn/share/a3b35db0-ab5e-4abc-b8d3-5ff284e82e7b
CVE-2023-38831HIGHunder attackransomware17 Jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC2
CVE-2024-4577 POC
CVE-2024-4577CRITICALunder attackransomware17 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC2
ggfzx/CVE-2024-36104
CVE-2024-36104CRITICAL17 Jun 2024
Apache OFBiz: Path traversal leading to a RCE
85RISK
open
GitHub PoC7
CVE-2024-23692
CVE-2024-23692CRITICALunder attackransomware17 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attackransomware17 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware17 Jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23334MEDIUM17 Jun 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC19
PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution
CVE-2024-38396CRITICAL16 Jun 2024
An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in
48RISK
open
VulnCheck XDB
local
CVE-2023-28252HIGHunder attackransomware16 Jun 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open
VulnCheck XDB
infoleak
CVE-2024-28995HIGHunder attack16 Jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attackransomware16 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
GitHub PoC
SolarWinds Serv-U Directory Traversal Vulnerability (CVE-2024-28995) POC
CVE-2024-28995HIGHunder attack16 Jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
GitHub PoC
CVE-2024-23692 exp
CVE-2024-23692CRITICALunder attackransomware16 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
GitHub PoC
The TL;DR for the learnings of Windows Vulnerability CVE-2023-28252
CVE-2023-28252HIGHunder attackransomware16 Jun 2024
Windows Common Log File System Driver Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
snapcreek_duplicator file read vulnerability https://www.cvedetails.com/cve/CVE-2020-11738/
CVE-2020-11738HIGHunder attack15 Jun 2024
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISK
open
GitHub PoC13
Argument injection vulnerability in PHP
CVE-2024-4577CRITICALunder attackransomware15 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Shadow-Spinner/CVE-2012-2982_python
CVE-2012-298215 Jun 2024
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware15 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-11738HIGHunder attack15 Jun 2024
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RISK
open
GitHub PoC
cve-2024/CVE-2024-4295-Poc
CVE-2024-4295CRITICAL14 Jun 2024
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISK
open
GitHub PoC
TikiWiki CMS Groupware v8.3 - Open Redirect
CVE-2012-532114 Jun 2024
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frame
43RISK
open
VulnCheck XDB
infoleak
CVE-2024-4295CRITICAL14 Jun 2024
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-28995HIGHunder attack14 Jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-28995HIGHunder attack14 Jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-28995HIGHunder attack14 Jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attackransomware14 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-28995HIGHunder attack14 Jun 2024
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
previouspage 381 / 2,563next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.