Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
77,020 exploits
GitHub PoC3
CVE-2024-4577 Exploit POC
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC9
Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands.
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware08 Jun 2024
Information disclosure
100RISK
open
GitHub PoC33
PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
satchhacker/cve-2024-24919
CVE-2024-24919HIGHunder attackransomware08 Jun 2024
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware08 Jun 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-29269HIGH08 Jun 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open
GitHub PoC
Autonomy Ultraseek - Open Redirect
CVE-2009-034708 Jun 2024
Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers
43RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
NSE script to check if app is vulnerable to cve-2023-22515
CVE-2023-22515CRITICALunder attackransomware08 Jun 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC6
CVE-2024-4577 nuclei-templates
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC162
[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。
CVE-2024-4577CRITICALunder attackransomware08 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
CVE-2021-22204 exploit script
CVE-2021-22204MEDIUMunder attack07 Jun 2024
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC
oracle weblogic
CVE-2020-14883HIGHunder attack07 Jun 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware07 Jun 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack07 Jun 2024
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALunder attackransomware07 Jun 2024
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISK
open
GitHub PoC2
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
CVE-2024-27956CRITICAL07 Jun 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jun 2024
Argument Injection in PHP-CGI
100RISK
open
previouspage 387 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.