Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,058 exploits
GitHub PoC
activemq-rce-cve-2023-46604
CVE-2023-46604CRITICALunder attackransomware26 Apr 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
libertycityhacker/CVE-2023-43364-Exploit-CVE
CVE-2023-43364CRITICAL26 Apr 2024
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware25 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC6
0xr2r/CVE-2024-3400-Palo-Alto-OS-Command-Injection
CVE-2024-3400CRITICALunder attackransomware25 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC6
POC for SQLi vulnerability in Icegram express
CVE-2024-2876CRITICAL25 Apr 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack25 Apr 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-2876CRITICAL25 Apr 2024
Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC14
rbih-boulanouar/CVE-2024-4040
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC42
CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.
CVE-2023-20198CRITICALunder attack25 Apr 2024
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC63
CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support
CVE-2024-4040CRITICALunder attack25 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
CVE-2019-9670CRITICALunder attack24 Apr 2024
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RISK
open
GitHub PoC6
Simple honeypot for CVE-2024-3400 Palo Alto PAN-OS Command Injection Vulnerability
CVE-2024-3400CRITICALunder attackransomware24 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC11
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793
CVE-2023-42793CRITICALunder attackransomware24 Apr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.
CVE-2024-3400CRITICALunder attackransomware24 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC4
PoC exploit for GLPI - Command injection using a third-party library script
CVE-2022-35914CRITICALunder attack24 Apr 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALunder attack24 Apr 2024
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware24 Apr 2024
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware24 Apr 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware23 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2024-3273HIGHunder attack23 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
Metasploit600
Flowmon Unauthenticated Command Injection
CVE-2024-2389CRITICAL23 Apr 2024
Flowmon Unauthenticated Command Injection Vulnerability
85RISK
open
GitHub PoC
A basic script that exploits CVE-2011-2523
CVE-2011-252323 Apr 2024
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
infoleak
CVE-2024-4040CRITICALunder attack23 Apr 2024
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
mrrobot0o/CVE-2024-3273-
CVE-2024-3273HIGHunder attack23 Apr 2024
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC36
CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
CVE-2024-27198CRITICALunder attackransomware22 Apr 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC6
A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read
CVE-2018-14847CRITICALunder attack22 Apr 2024
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
previouspage 404 / 2,569next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.