Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
77,058 exploits
GitHub PoC54
Information for CVE-2024-3094
CVE-2024-3094CRITICAL29 Mar 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC4
Verify that your XZ Utils version is not vulnerable to CVE-2024-3094
CVE-2024-3094CRITICAL29 Mar 2024
Xz: malicious code in distributed source
70RISK
open
GitHub PoC6
ShadowRay RCE POC (CVE-2023-48022)
CVE-2023-48022CRITICAL29 Mar 2024
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RISK
open
GitHub PoC8
This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.
CVE-2024-1698CRITICAL29 Mar 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC
Fractal-Tess/CVE-2024-3094
CVE-2024-3094CRITICAL29 Mar 2024
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-48022CRITICAL29 Mar 2024
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the ve
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-1698CRITICAL29 Mar 2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-35078CRITICALunder attackransomware29 Mar 2024
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2019-0708CRITICALunder attackransomware28 Mar 2024
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
Bludit 3.9.2 auth bruteforce bypass
CVE-2019-17240LOW28 Mar 2024
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack28 Mar 2024
Unauthenticated Command Injection
100RISK
open
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2015-1701HIGHunder attackransomware28 Mar 2024
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISK
open
GitHub PoC
mind2hex/CVE-2022-46169-Cacti-v1.2.22-RCE
CVE-2022-46169CRITICALunder attack28 Mar 2024
Unauthenticated Command Injection
100RISK
open
GitHub PoC
A working POC found while doing a HTB challenge. Original: https://github.com/user0x1337/CVE-2022-39227
CVE-2022-39227CRITICAL28 Mar 2024
Python-jwt subject to Authentication Bypass by Spoofing
48RISK
open
GitHub PoC1
Check CVE-2023-42789
CVE-2023-42789CRITICAL28 Mar 2024
A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0
48RISK
open
Metasploit600
pgAdmin Binary Path API RCE
CVE-2024-3116HIGH28 Mar 2024
Remote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
48RISK
open
GitHub PoC
Sumitpathania03/Apache-RocketMQ-CVE-2023-33246-
CVE-2023-33246CRITICALunder attack28 Mar 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2012-0003HIGH28 Mar 2024
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RISK
open
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2010-3333HIGHunder attack28 Mar 2024
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALunder attack28 Mar 2024
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2014-4114HIGHunder attack28 Mar 2024
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RISK
open
GitHub PoC
ecrit un script python de correction de la vulnérabilités windows 7 pour réponse automatique de wazuh: CVE-2017-0143 (MS17-010 - EternalBlue) CVE-2019-0708 (BlueKeep), CVE-2019-1181 / CVE-2019-1182 (BlueKeep II), CVE-2015-1701 (MS15-034), CVE-2010-3333 (MS10-092), CVE-2012-0003 (MS12-020), CVE-2017-8759, CVE-2014-4114
CVE-2017-0143HIGHunder attackransomware28 Mar 2024
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC1
Bludit 3.9.2 Remote Command Execution (RCE)
CVE-2019-1611328 Mar 2024
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISK
open
GitHub PoC5
it's a CVE-2023-28229 (Patched), but feel free to use it for check any outdated software or reseach
CVE-2023-28229HIGHunder attack27 Mar 2024
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack27 Mar 2024
Grafana path traversal
100RISK
open
GitHub PoC5
Unauthenticated Remote Code Execution (RCE) Vulnerability in WWBNIndex Plugin of AVideo Platform from 12.4 to 14.2
CVE-2024-31819CRITICAL27 Mar 2024
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath
68RISK
open
GitHub PoC
ticofookfook/CVE-2021-43798
CVE-2021-43798HIGHunder attack27 Mar 2024
Grafana path traversal
100RISK
open
VulnCheck XDB
local
CVE-2023-28229HIGHunder attack27 Mar 2024
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
infoleak
CVE-2024-20767HIGHunder attack26 Mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-20767HIGHunder attack26 Mar 2024
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
previouspage 413 / 2,569next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.