Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
77,020 exploits
GitHub PoC20
PoC for the Veeam Recovery Orchestrator Authentication CVE-2024-29855
CVE-2024-29855CRITICAL13 Jun 2024
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
53RISK
open
GitHub PoC11
vanboomqi/CVE-2024-23692
CVE-2024-23692CRITICALunder attackransomware13 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
GitHub PoC
HPT-Intern-Task-Submission/CVE-2022-46169
CVE-2022-46169CRITICALunder attack12 Jun 2024
Unauthenticated Command Injection
100RISK
open
GitHub PoC25
Ivanti EPM SQL Injection Remote Code Execution Vulnerability
CVE-2024-29824CRITICALunder attack12 Jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISK
open
GitHub PoC
Rejetto http File Server 2.3.x (Reverse shell)
CVE-2014-6287CRITICALunder attack12 Jun 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC4
jakabakos/CVE-2024-27348-Apache-HugeGraph-RCE
CVE-2024-27348CRITICALunder attack12 Jun 2024
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
GitHub PoC
raytran54/CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware12 Jun 2024
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
0XFFFF-XD/CVE-2024-4577-PHP-CGI-RCE
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Vietnam National Cyber Security (NCS)'s Internship - 2nd Test
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
CVE-2024-3922CRITICAL12 Jun 2024
Dokan Pro <= 3.10.3 - Unauthenticated SQL Injection
75RISK
open
GitHub PoC5
CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC2
POC for CVE-2024-4577 with Shodan integration
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack12 Jun 2024
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-4898CRITICAL12 Jun 2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-29824CRITICALunder attack12 Jun 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27348CRITICALunder attack12 Jun 2024
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0352HIGH12 Jun 2024
Likeshop HTTP POST Request File.php userFormImage unrestricted upload
78RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack12 Jun 2024
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-23692CRITICALunder attackransomware11 Jun 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware11 Jun 2024
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware11 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
local
CVE-2023-20598HIGH11 Jun 2024
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an I
41RISK
open
VulnCheck XDB
local
CVE-2024-26229HIGH11 Jun 2024
Windows CSC Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC1
SalehLardhi/CVE-2024-24919
CVE-2024-24919HIGHunder attackransomware11 Jun 2024
Information disclosure
100RISK
open
Metasploit600
Windows Kernel Time of Check Time of Use LPE in AuthzBasepCopyoutInternalSecurityAttributes
CVE-2024-30038HIGH11 Jun 2024
Win32k Elevation of Privilege Vulnerability
36RISK
open
GitHub PoC29
CVE-2024-37051 poc and exploit
CVE-2024-37051CRITICAL11 Jun 2024
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ
48RISK
open
previouspage 385 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.