Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,058 exploits
GitHub PoC
PoC for CVE-2023-32749 affecting Pydio Cells
CVE-2023-32749HIGH01 May 2024
Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying t
46RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack01 May 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL01 May 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALunder attackransomware30 Apr 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
VulnCheck XDB
local
CVE-2024-1086HIGHunder attackransomware30 Apr 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALunder attack30 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
CCIEVoice2009/CVE-2024-1086
CVE-2024-1086HIGHunder attackransomware30 Apr 2024
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALunder attackransomware30 Apr 2024
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware30 Apr 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC7
A remote code execution vulnerability exists in the iControl REST API feature of F5's BIG-IP product. An unauthenticated, remote attacker can exploit this to bypass authentication and execute arbitrary commands with root privileges.
CVE-2022-1388CRITICALunder attackransomware30 Apr 2024
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RISK
open
GitHub PoC
Update of https://github.com/1337g/CVE-2017-12149 to work with python3
CVE-2017-12149CRITICALunder attackransomware30 Apr 2024
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC5
Exploit CrushFTP CVE-2024-4040
CVE-2024-4040CRITICALunder attack30 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
Exploit for CVE-2024-4040 affecting CrushFTP server in all versions before 10.7.1 and 11.1.0 on all platforms
CVE-2024-4040CRITICALunder attack29 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack29 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-2667CRITICAL28 Apr 2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
63RISK
open
GitHub PoC2
This is POC for CVE-2024-2667 (InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload)
CVE-2024-2667CRITICAL28 Apr 2024
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
63RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack28 Apr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC1
nahcusira/CVE-2021-26084
CVE-2021-26084CRITICALunder attackransomware28 Apr 2024
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
exploit for CVE-2024-4040
CVE-2024-4040CRITICALunder attack28 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
client-side
CVE-2021-4206328 Apr 2024
A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage
43RISK
open
GitHub PoC
A simple bash script to exploit Joomla! < 4.2.8 - Unauthenticated information disclosure
CVE-2023-23752MEDIUMunder attack28 Apr 2024
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware27 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
This repository contains a proof of concept about the exploitation of the aiohttp library for the reported vulnerability CVE-2024-23334.
CVE-2024-23334MEDIUM27 Apr 2024
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL27 Apr 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC2
Exploit for GlobalProtect CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware27 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
CVE-2024-27956 WordPress Automatic < 3.92.1 - Unauthenticated SQL Injection
CVE-2024-27956CRITICAL27 Apr 2024
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
GitHub PoC2
NSE script for checking the presence of CVE-2023-22515
CVE-2023-22515CRITICALunder attackransomware26 Apr 2024
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
libertycityhacker/CVE-2023-43364-Exploit-CVE
CVE-2023-43364CRITICAL26 Apr 2024
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
48RISK
open
GitHub PoC
activemq-rce-cve-2023-46604
CVE-2023-46604CRITICALunder attackransomware26 Apr 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
LamSonBinh/CVE-2018-20250
CVE-2018-20250HIGHunder attackransomware26 Apr 2024
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RISK
open
previouspage 403 / 2,569next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.