Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
77,058 exploits
GitHub PoC★ 3,555
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 1
hapa3/CVE-2024-31666
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon
48RISK
open ↗GitHub PoC
spidygal/CVE-2024-3094-Nmap-NSE-script
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 4
A script to detect if xz is vulnerable - CVE-2024-3094
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC
Ansible playbook for patching CVE-2024-3094
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 1
upgraded of BlueBourne CVE-2017-0785 to python3
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RISK
open ↗GitHub PoC★ 10
History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 11
K8S and Docker Vulnerability Check for CVE-2024-3094
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 1
Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code.
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 1
efekaanakkar/CVE-2024-30998
SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrar
48RISK
open ↗GitHub PoC★ 147
An ssh honeypot with the XZ backdoor. CVE-2024-3094
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 2
Horizon-Software-Development/CVE-2024-3094
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 26
Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6) or upgrading to latest version. Added Ansible Playbook
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC
More specific : Dirty COW (CVE-2016-5195)
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗VulnCheck XDB
infoleak
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RISK
open ↗VulnCheck XDB
initial-access
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open ↗VulnCheck XDB
local
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open ↗VulnCheck XDB
initial-access
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RISK
open ↗VulnCheck XDB
initial-access
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open ↗GitHub PoC★ 4
Verify that your XZ Utils version is not vulnerable to CVE-2024-3094
Xz: malicious code in distributed source
70RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.