Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
77,020 exploits
GitHub PoC4
CVE-2024-29275.yaml
CVE-2024-29275CRITICAL20 Jun 2024
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code an
48RISK
open
GitHub PoC
CVE-2023-2825 exploit script
CVE-2023-2825CRITICAL20 Jun 2024
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
GitHub PoC1
rdoix/cve-2024-21762-checker
CVE-2024-21762CRITICALunder attackransomware20 Jun 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
GitHub PoC6
This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).
CVE-2019-905320 Jun 2024
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
infoleak
CVE-2023-2825CRITICAL20 Jun 2024
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RISK
open
VulnCheck XDB
local
CVE-2019-13272HIGHunder attack20 Jun 2024
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL20 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
GitHub PoC3
This is a Python 3 version of this exploit. Hope it works!!!
CVE-2019-13272HIGHunder attack20 Jun 2024
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
VulnCheck XDB
infoleak
CVE-2024-21762CRITICALunder attackransomware20 Jun 2024
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-29972CRITICAL20 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326
85RISK
open
GitHub PoC
CVE-2022-22947 exploit script
CVE-2022-22947CRITICALunder attack19 Jun 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
MalekAlthubiany/CVE-2021-43798
CVE-2021-43798HIGHunder attack19 Jun 2024
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack19 Jun 2024
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware19 Jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC3
momika233/CVE-2024-29973
CVE-2024-29973CRITICAL19 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
GitHub PoC72
CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.
CVE-2024-28397MEDIUM19 Jun 2024
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
CVE-2023-38831HIGHunder attackransomware19 Jun 2024
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC10
POC for CVE-2024-29973
CVE-2024-29973CRITICAL19 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
GitHub PoC6
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
CVE-2024-4367MEDIUM19 Jun 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL19 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-29973CRITICAL19 Jun 2024
** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar
85RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack19 Jun 2024
Grafana path traversal
100RISK
open
GitHub PoC
jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE
CVE-2024-4577CRITICALunder attackransomware18 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack18 Jun 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
A small tool to create a PoC for CVE-2000-0649.
CVE-2000-064918 Jun 2024
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISK
open
GitHub PoC13
CVE-2024-23692 Exploit
CVE-2024-23692CRITICALunder attackransomware18 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware18 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Redfox-Security/Digisol-DG-GR1321-s-Password-Policy-Bypass-CVE-2024-2257
CVE-2024-2257CRITICAL18 Jun 2024
Password Policy Bypass Vulnerability in Digisol Router
48RISK
open
GitHub PoC1
Ivanti EPM SQL Injection Remote Code Execution Vulnerability(Optimized version based on h3)
CVE-2024-29824CRITICALunder attack18 Jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISK
open
Metasploit500
vCenter Sudo Privilege Escalation
CVE-2024-37081HIGH18 Jun 2024
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An auth
36RISK
open
previouspage 382 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.