Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,301GitHub PoC 14,141VulnCheck XDB 8,646Nuclei 4,289Metasploit 3,474✓ verified onlyrecentpopularrisk
77,133 exploits
GitHub PoC
Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open ↗VulnCheck XDB
initial-access
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗GitHub PoC
Shubham-2k1/Exploit-CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗VulnCheck XDB
initial-access
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗GitHub PoC★ 43
ActiveMQ RCE (CVE-2023-46604) 回显利用工具
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗Metasploit600
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RISK
open ↗GitHub PoC★ 37
Exploit for CVE-2024-27198 - TeamCity Server
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗GitHub PoC★ 4
A PoC exploit for CVE-2021-43798 - Grafana Directory Traversal
Grafana path traversal
100RISK
open ↗GitHub PoC★ 3
CVE-2024-1071 with Docker
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
85RISK
open ↗GitHub PoC★ 1
This script will help you to scan for smbGhost vulnerability(CVE-2020-0796)
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗GitHub PoC★ 6
Three go-exploits exploiting CVE-2023-22527 to execute arbitrary code in memory
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open ↗Metasploit600
JetBrains TeamCity Unauthenticated Remote Code Execution
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗GitHub PoC★ 36
Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗VulnCheck XDB
initial-access
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open ↗VulnCheck XDB
initial-access
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗Metasploit600
pgAdmin Session Deserialization RCE
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
65RISK
open ↗Metasploit600
Judge0 sandbox escape
Judge0 vulnerable to Sandbox Escape Patch Bypass via chown running on Symbolic Link
43RISK
open ↗Exploit-DB
Petrol Pump Management Software v.1.0 - Stored Cross Site Scripting via SVG file
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code
33RISK
open ↗Exploit-DB
Petrol Pump Management Software v1.0 - 'Address' Stored Cross Site Scripting
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code
33RISK
open ↗Exploit-DB
Petrol Pump Management Software v.1.0 - SQL Injection
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a c
53RISK
open ↗Exploit-DB
Petrol Pump Management Software v1.0 - Remote Code Execution via File Upload
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a cra
53RISK
open ↗GitHub PoC
RxRCoder/CVE-2023-2437
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RISK
open ↗GitHub PoC★ 2
abian2/CVE-2024-23652
BuildKit possible host system access from mount stub cleaner
48RISK
open ↗GitHub PoC★ 2
PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
85RISK
open ↗VulnCheck XDB
remote-with-credentials
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.