Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
77,020 exploits
GitHub PoC4
conan-sudo/CVE-2019-14974-bypass
CVE-2019-1497406 Jun 2024
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
50RISK
open
GitHub PoC
CVE-2024-4295 Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
CVE-2024-4295CRITICAL06 Jun 2024
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL06 Jun 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware06 Jun 2024
Information disclosure
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack06 Jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-133506 Jun 2024
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-1472MEDIUMunder attackransomware06 Jun 2024
Netlogon Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-5324HIGH06 Jun 2024
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-4358CRITICALunder attack05 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4295CRITICAL05 Jun 2024
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISK
open
GitHub PoC
CVE-2021-1675/CVE-2021-34527 PrintNightmare & CVE-2020-0668
CVE-2021-1675HIGHunder attackransomware05 Jun 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps.
CVE-2023-22515CRITICALunder attackransomware05 Jun 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
local
CVE-2021-1675HIGHunder attackransomware05 Jun 2024
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC26
Sk1dr0wz/CVE-2024-4358_Mass_Exploit
CVE-2024-4358CRITICALunder attack05 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
GitHub PoC1
Oracle WebLogic Server (LFI)
CVE-2022-21371HIGH05 Jun 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
GitHub PoC
CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit
CVE-2017-891705 Jun 2024
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open
GitHub PoC9
CVE-2024-4956 Python exploitation utility
CVE-2024-4956HIGH05 Jun 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC1
muhammad1596/CVE-2022-0847-dirty-pipe-checker
CVE-2022-0847HIGHunder attack04 Jun 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC2
Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16
CVE-2024-21111HIGH04 Jun 2024
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISK
open
GitHub PoC1
0xans/CVE-2024-24919
CVE-2024-24919HIGHunder attackransomware04 Jun 2024
Information disclosure
100RISK
open
GitHub PoC
Tim-Hoekstra/CVE-2024-24919
CVE-2024-24919HIGHunder attackransomware04 Jun 2024
Information disclosure
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware04 Jun 2024
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-21683HIGH04 Jun 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISK
open
VulnCheck XDB
local
CVE-2024-2961HIGH04 Jun 2024
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMunder attack04 Jun 2024
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC
Harydhk7/CVE-2024-4358
CVE-2024-4358CRITICALunder attack04 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4358CRITICALunder attack04 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4358CRITICALunder attack04 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
Metasploit600
Telerik Report Server Auth Bypass and Deserialization RCE
CVE-2024-4358CRITICALunder attack04 Jun 2024
Registration Authentication Bypass Vulnerability
100RISK
open
GitHub PoC
junnythemarksman/CVE-2023-30547
CVE-2023-30547CRITICAL04 Jun 2024
Sandbox Escape in vm2
70RISK
open
previouspage 389 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.