Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,020 exploits
GitHub PoC2
CVE-2024-4443 Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter
CVE-2024-4443CRITICAL26 May 2024
Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter
68RISK
open
GitHub PoC
WordPress Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVE-2024-5084CRITICAL25 May 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
Metasploit600
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
CVE-2024-23692CRITICALunder attackransomware25 May 2024
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
GitHub PoC
Wordpress - Copymatic – AI Content Writer & Generator <= 1.6 - Unauthenticated Arbitrary File Upload
CVE-2024-31351CRITICAL25 May 2024
WordPress Copymatic plugin <= 1.6 - Unauthenticated Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC1
Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion
CVE-2020-3452HIGHunder attack25 May 2024
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC
A submodule to demonstrate CVE-2024-32002. Demonstrates arbitrary write into .git.
CVE-2024-32002CRITICAL25 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
A POC for CVE-2024-32002 demonstrating arbitrary write into the .git directory.
CVE-2024-32002CRITICAL25 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
part of poc cve-2024-32002
CVE-2024-32002CRITICAL24 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC2
Unauthenticated Path Traversal in Nexus Repository 3
CVE-2024-4956HIGH24 May 2024
Nexus Repository 3 - Path Traversal
61RISK
open
Metasploit300
Ivanti EPM RecordGoodApp SQLi RCE
CVE-2024-29824CRITICALunder attack24 May 2024
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att
100RISK
open
GitHub PoC4
POC for ImageMagick 6.9.6-4. This is a POC which was inspired by fullwaywang discovery of CVE-2023-34152.
CVE-2023-34152CRITICAL23 May 2024
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob wit
48RISK
open
Metasploit600
WordPress Hash Form Plugin RCE
CVE-2024-5084CRITICAL23 May 2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
GitHub PoC8
CVE-2024-3495 Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
CVE-2024-3495CRITICAL23 May 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISK
open
GitHub PoC1
poc of git rce using cve-2024-32002
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC3
CVE-2024-4956 Nuclei Template
CVE-2024-4956HIGH23 May 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC3
Unauthenticated Path Traversal in Nexus Repository 3
CVE-2024-4956HIGH23 May 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC
PoC Exploit for CVE-2024-32002
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC2
10cks/CVE-2024-32002-EXP
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC1
Nexus Repository Manager 3 Unauthenticated Path Traversal
CVE-2024-4956HIGH23 May 2024
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC
PoC Exploit for CVE-2024-32002
CVE-2024-32002CRITICAL23 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-21683HIGH23 May 2024
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISK
open
VulnCheck XDB
infoleak
CVE-2024-3495CRITICAL23 May 2024
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
68RISK
open
GitHub PoC1
CVE-2024-4367 mitigation for Odoo 14.0
CVE-2024-4367MEDIUM23 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC4
The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based clients and servers using a version of FreeRDP prior to version 3.5.0 or 2.11.6 are vulnerable to out-of-bounds reading12. Versions 3.5.0 and 2.11.6 correct the problem
CVE-2024-32459CRITICAL22 May 2024
FreeRDP Out-Of-Bounds Read in ncrush_decompress
48RISK
open
GitHub PoC11
YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js
CVE-2024-4367MEDIUM22 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC4
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
CVE-2024-4367MEDIUM22 May 2024
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
Presentazione per il corsi di sicurezza Informatica sulla vulnerabilità CVE-2024-3094
CVE-2024-3094CRITICAL22 May 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Proof Of Concept for the CVE-2016-10033 (PHPMailer)
CVE-2016-10033CRITICALunder attack22 May 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC
Repo for testing CVE-2024-32002
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
1mxml/CVE-2024-32002-poc
CVE-2024-32002CRITICAL22 May 2024
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
previouspage 395 / 2,568next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.