Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
77,058 exploits
VulnCheck XDB
initial-access
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RISK
open ↗GitHub PoC★ 3
apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links
Xz: malicious code in distributed source
70RISK
open ↗Exploit-DB
Daily Habit Tracker 1.0 - Broken Access Control
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,
53RISK
open ↗Exploit-DB
Daily Habit Tracker 1.0 - Stored Cross-Site Scripting (XSS)
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via t
38RISK
open ↗Exploit-DB
Axigen < 10.5.7 - Persistent Cross-Site Scripting
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges
48RISK
open ↗GitHub PoC★ 1
cjybao/CVE-2024-1709-and-CVE-2024-1708
Authentication bypass using an alternate path or channel
100RISK
open ↗GitHub PoC
Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.
Xz: malicious code in distributed source
70RISK
open ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗Exploit-DB
Daily Habit Tracker 1.0 - SQL Injection
SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit
48RISK
open ↗Exploit-DB
Gibbon LMS v26.0.00 - SSTI vulnerability
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re
53RISK
open ↗GitHub PoC★ 14
Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 3
CVE-2024-3094 - Checker (fix for arch etc)
Xz: malicious code in distributed source
70RISK
open ↗Exploit-DB
GL-iNet MT6000 4.5.5 - Arbitrary File Download
An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially
46RISK
open ↗Exploit-DB
Employee Management System 1.0 - _txtusername_ and _txtpassword_ SQL Injection (Admin Login)
20RISK
open ↗GitHub PoC★ 1
Exploit for CVE-2024-20767 affecting Adobe ColdFusion
ColdFusion | Improper Access Control (CWE-284)
100RISK
open ↗GitHub PoC★ 3
Herramientas de linux para diferentes funciones.
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 3,555
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 17
XZ Backdoor Extract(Test on Ubuntu 23.10)
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC
This is my malware
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.