Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,058 exploits
GitHub PoC
Vulnerabilidad de palo alto
CVE-2024-3400CRITICALunder attackransomware14 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
Simple CVE-2024-24576 PoC in Julia
CVE-2024-24576CRITICAL14 Apr 2024
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
53RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack14 Apr 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC1
Python script for CMS Made Simple 2.1.6 - Remote Code Execution.
CVE-2018-744814 Apr 2024
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RISK
open
GitHub PoC13
momika233/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware14 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
cve-2020-1938 Tomcat-Ajp-lfi.git脚本
CVE-2020-1938CRITICALunder attack14 Apr 2024
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC336
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
CVE-2024-21338HIGHunder attackransomware13 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
Demonstration of CVE-2020-11023
CVE-2020-11023MEDIUMunder attack13 Apr 2024
Potential XSS vulnerability in jQuery
85RISK
open
GitHub PoC11
Yuvvi01/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y 5.6.1 de la herramienta de compresión XZ.
CVE-2024-3094CRITICAL13 Apr 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
MAL-004: Command Injection Bypass for CVE-2020-12641 in Roundcube Webmail
CVE-2020-12641CRITICALunder attack13 Apr 2024
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
100RISK
open
GitHub PoC2
PoC MinIO vulnerability exploit
CVE-2023-28432HIGHunder attack13 Apr 2024
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail
CVE-2020-13965MEDIUMunder attack13 Apr 2024
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML atta
85RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware13 Apr 2024
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2023-28432HIGHunder attack13 Apr 2024
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC
CVE-2024-21413 Setup for CW
CVE-2024-21413CRITICALunder attack13 Apr 2024
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
FoxyProxys/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC2
CerTusHack/CVE-2024-3400-PoC
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC72
CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware13 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack12 Apr 2024
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
Exploit-DB
GUnet OpenEclass E-learning platform 3.15 - 'certbadge.php' Unrestricted File Upload
CVE-2024-31777CRITICALwebappsphp12 Apr 2024
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil
48RISK
open
Metasploit600
Palo Alto Networks PAN-OS Unauthenticated Remote Code Execution
CVE-2024-3400CRITICALunder attackransomware12 Apr 2024
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
Metasploit300
Netdata ndsudo privilege escalation
CVE-2024-32019HIGH12 Apr 2024
ndsudo: local privilege escalation via untrusted search path
36RISK
open
GitHub PoC5
OpenMetadata_RCE (CVE-2024-28255) Batch scan/exploit
CVE-2024-28255CRITICAL12 Apr 2024
Authentication Bypass in OpenMetadata
85RISK
open
Exploit-DB
Ray OS v2.6.3 - Command Injection RCE(Unauthorized)
CVE-2023-6019CRITICALwebappspython12 Apr 2024
Ray Command Injection in cpu_profile Parameter
85RISK
open
Exploit-DB
MinIO < 2024-01-31T20-20-33Z - Privilege Escalation
CVE-2024-24747HIGHremotego12 Apr 2024
MinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
53RISK
open
VulnCheck XDB
initial-access
CVE-2024-29269HIGH12 Apr 2024
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the
56RISK
open
VulnCheck XDB
initial-access
CVE-2024-28255CRITICAL12 Apr 2024
Authentication Bypass in OpenMetadata
85RISK
open
GitHub PoC50
CVE-2023-6319 proof of concept
CVE-2023-6319CRITICAL11 Apr 2024
Command injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-2389CRITICAL11 Apr 2024
Flowmon Unauthenticated Command Injection Vulnerability
85RISK
open
previouspage 408 / 2,569next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.