Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,058 exploits
GitHub PoC2
Extract useful information from PANOS support file for CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware19 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
Finding Palo Alto devices vulnerable to CVE-2024-3400.
CVE-2024-3400CRITICALunder attackransomware19 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
ASG-CASTLE/CVE-2021-4034
CVE-2021-4034HIGHunder attack19 Apr 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
Whiteh4tWolf/CVE-2024-1651-PoC
CVE-2024-1651CRITICAL19 Apr 2024
Torrentpier 2.4.1 - RCE
60RISK
open
GitHub PoC2
Proof of concept for CVE-2022-0847
CVE-2022-0847HIGHunder attack19 Apr 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack19 Apr 2024
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC6
schooldropout1337/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
Script that exploits the vulnerability of the ProFTPd 1.3.5 service with CVE-2015-3306
CVE-2015-330618 Apr 2024
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC
EDL for IPs attacking customers with CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
CVE-2024-3400 POC written in Rust and Python
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
sxyrxyy/CVE-2024-3400-Check
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC5
XZ Utils CVE-2024-3094 POC for Kubernetes
CVE-2024-3094CRITICAL18 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Script that exploits the vulnerability that allows establishing a backdoor in the UnrealIRCd service with CVE-2010-2075
CVE-2010-207518 Apr 2024
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
Script that exploits the vulnerability that allows remote code execution in Ruby 2.3.8 ​​with CVE-2016-2098
CVE-2016-209818 Apr 2024
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-0305MEDIUM18 Apr 2024
Guangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
60RISK
open
GitHub PoC
Simple Python code to check for arbitrary uploading for PaloAlto CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
Simple POC for CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware18 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
Fork of https://github.com/hakaioffsec/CVE-2024-21338
CVE-2024-21338HIGHunder attackransomware17 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC4
A go-exploit for Apache ActiveMQ CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware17 Apr 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC2
Have we not learnt from HoneyPoC?
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
command injection
CVE-2024-1874CRITICAL17 Apr 2024
Command injection via array-ish $command parameter of proc_open()
60RISK
open
GitHub PoC9
Global Protec Palo Alto File Write Exploit
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
A check program for CVE-2024-3400, Palo Alto PAN-OS unauthenticated command injection vulnerability. Palo Alto 防火墙 PAN-OS 远程命令注入检测程序。
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-25194HIGH17 Apr 2024
Apache Kafka Connect API: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration using Kafka Connect
78RISK
open
GitHub PoC5
CVE-2024-3400 : Palo Alto OS Command Injection - POC
CVE-2024-3400CRITICALunder attackransomware17 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware17 Apr 2024
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware17 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
previouspage 406 / 2,569next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.