Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
77,151 exploits
VulnCheck XDB
local
CVE-2023-32233HIGH04 Feb 2024
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack04 Feb 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC1
Triggering the famous libweb 0day vuln with libfuzzer
CVE-2023-4863HIGHunder attack04 Feb 2024
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC
Shellshock exploit (CVE-2014-6271)
CVE-2014-6271CRITICALunder attack04 Feb 2024
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC2
wechicken456/CVE-2021-4034-CTF-writeup
CVE-2021-4034HIGHunder attack04 Feb 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
WLXQqwer/Jenkins-CVE-2024-23897-
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
xMr110/CVE-2020-14882
CVE-2020-14882CRITICALunder attack04 Feb 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC22
Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC1
GoAnywhere MFT
CVE-2024-0204CRITICAL04 Feb 2024
Authentication Bypass in GoAnywhere MFT
85RISK
open
GitHub PoC5
Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite
CVE-2019-2215HIGHunder attack04 Feb 2024
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC
semcms存在SQL注入(CVE-2024-25422 )
CVE-2024-25422CRITICAL04 Feb 2024
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0204CRITICAL04 Feb 2024
Authentication Bypass in GoAnywhere MFT
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware04 Feb 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
CharonDefalt/Juniper-exploit-CVE-2023-36845
CVE-2023-36845CRITICALunder attack03 Feb 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-21893HIGHunder attackransomware03 Feb 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-21887CRITICALunder attackransomware03 Feb 2024
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALunder attack03 Feb 2024
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC27
CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit
CVE-2024-21893HIGHunder attackransomware03 Feb 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RISK
open
GitHub PoC94
CVE-2024-21893: SSRF Vulnerability in Ivanti Connect Secure
CVE-2024-21893HIGHunder attackransomware02 Feb 2024
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy
100RISK
open
GitHub PoC
Trinadh465/external_zlib_android-6.0.1_r22_CVE-2022-37434
CVE-2022-37434CRITICAL02 Feb 2024
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header
53RISK
open
GitHub PoC
Trinadh465/external_zlib_CVE-2022-37434
CVE-2022-37434CRITICAL02 Feb 2024
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header
53RISK
open
VulnCheck XDB
initial-access
CVE-2024-0204CRITICAL02 Feb 2024
Authentication Bypass in GoAnywhere MFT
85RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack02 Feb 2024
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
CVE-2023-22527 Batch scanning
CVE-2023-22527CRITICALunder attackransomware02 Feb 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH02 Feb 2024
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
VulnCheck XDB
initial-access
CVE-2023-22527CRITICALunder attackransomware02 Feb 2024
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH02 Feb 2024
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH02 Feb 2024
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH02 Feb 2024
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
previouspage 426 / 2,572next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.