Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
77,151 exploits
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware29 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware29 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC17
This repository presents a proof-of-concept of CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware28 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-6933HIGH28 Jan 2024
Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
68RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware28 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
132231g/CVE-2019-3398
CVE-2019-3398HIGHunder attack28 Jan 2024
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open
GitHub PoC
Samba 3.0.0 - 3.0.25rc3
CVE-2007-244728 Jan 2024
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
CVE-2024-23897CRITICALunder attackransomware28 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864628 Jan 2024
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-3398HIGHunder attack28 Jan 2024
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RISK
open
GitHub PoC1
GitLab CVE-2023-7028
CVE-2023-7028CRITICALunder attack28 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack28 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
GitHub PoC
gy741/CVE-2023-30258-setup
CVE-2023-30258CRITICAL27 Jan 2024
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
GitHub PoC86
CVE-2024-23897 - Jenkins 任意文件读取 利用工具
CVE-2024-23897CRITICALunder attackransomware27 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-6875CRITICAL27 Jan 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware27 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack27 Jan 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
FancySauce/PwnKit-CVE-2021-4034
CVE-2021-4034HIGHunder attack27 Jan 2024
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC15
CVE-2024-23897 jenkins-cli
CVE-2024-23897CRITICALunder attackransomware27 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC5
Scanner for CVE-2024-23897 - Jenkins
CVE-2024-23897CRITICALunder attackransomware27 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC6
Exploit for CVE-2023-6875 - Unauthorized Account Takeover.
CVE-2023-6875CRITICAL27 Jan 2024
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RISK
open
GitHub PoC4
on this git you can find all information on the CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware27 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC207
CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware26 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC80
CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.
CVE-2024-23897CRITICALunder attackransomware26 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
Python Code for Exploit Automation CVE-2023-7028
CVE-2023-7028CRITICALunder attack26 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack26 Jan 2024
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack26 Jan 2024
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware26 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware26 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware26 Jan 2024
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
previouspage 428 / 2,572next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.