Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,044 exploits
VulnCheck XDB
infoleak
CVE-2024-32640CRITICAL17 May 2024
MasaCMS SQL Injection vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-29895CRITICAL17 May 2024
Cacti command injection in cmd_realtime.php
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-27130HIGH17 May 2024
QTS, QuTS hero
53RISK
open
VulnCheck XDB
initial-access
CVE-2024-29895CRITICAL16 May 2024
Cacti command injection in cmd_realtime.php
85RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack16 May 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-32640CRITICAL16 May 2024
MasaCMS SQL Injection vulnerability
85RISK
open
VulnCheck XDB
client-side
CVE-2020-0601HIGHunder attack16 May 2024
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
VulnCheck XDB
initial-access
CVE-2024-29895CRITICAL16 May 2024
Cacti command injection in cmd_realtime.php
85RISK
open
GitHub PoC78
CVE-2024-32640 | Automated SQLi Exploitation PoC
CVE-2024-32640CRITICAL16 May 2024
MasaCMS SQL Injection vulnerability
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware16 May 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and https://github.com/ly4k/CurveBall
CVE-2020-0601HIGHunder attack16 May 2024
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RISK
open
GitHub PoC
ticofookfook/CVE-2024-29895.py
CVE-2024-29895CRITICAL16 May 2024
Cacti command injection in cmd_realtime.php
85RISK
open
GitHub PoC1
Cacti CVE-2024-29895 POC
CVE-2024-29895CRITICAL16 May 2024
Cacti command injection in cmd_realtime.php
85RISK
open
GitHub PoC
CVE-2016-10033 Wordpress 4.6 Exploit
CVE-2016-10033CRITICALunder attack16 May 2024
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC13
Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados
CVE-2024-23897CRITICALunder attackransomware16 May 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC23
CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds
CVE-2024-29895CRITICAL15 May 2024
Cacti command injection in cmd_realtime.php
85RISK
open
GitHub PoC1
PoC for CVE-2018-14716
CVE-2018-1471615 May 2024
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques
35RISK
open
GitHub PoC
W3BW/CVE-2024-27956-RCE-File-Package
CVE-2024-27956CRITICAL15 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC1
PoC for CVE-2021-34646
CVE-2021-34646CRITICAL15 May 2024
Booster for WooCommerce <= 5.4.3 Authentication Bypass
60RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH15 May 2024
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL15 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-29895CRITICAL15 May 2024
Cacti command injection in cmd_realtime.php
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL14 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC4
High CVE-2024-4761 Exploit
CVE-2024-4761HIGHunder attack14 May 2024
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds
76RISK
open
GitHub PoC5
jakabakos/CVE-2023-26360-adobe-coldfusion-rce-exploit
CVE-2023-26360HIGHunder attack14 May 2024
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
GitHub PoC
CVE-2024-34832
CVE-2024-34832CRITICAL14 May 2024
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a craf
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-26360HIGHunder attack14 May 2024
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
GitHub PoC15
aelmokhtar/CVE-2024-34716
CVE-2024-34716CRITICAL14 May 2024
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISK
open
GitHub PoC2
Checker for CVE-2021-3156 with static version check
CVE-2021-3156HIGHunder attack14 May 2024
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC2
POC for CVE-2024-4701
CVE-2024-4701CRITICAL13 May 2024
Path Traversal vulnerability via File Uploads in Genie
53RISK
open
previouspage 399 / 2,569next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.