Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
initial-access
CVE-2023-1698CRITICAL21 Feb 2025
WAGO: WBM Command Injection in multiple products
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH20 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALunder attack20 Feb 2025
Remote code execution in Wazuh server
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack19 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack19 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack19 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
client-side
CVE-2025-0411HIGHunder attack19 Feb 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack19 Feb 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
VulnCheck XDB
infoleak
CVE-2024-13159CRITICALunder attack18 Feb 2025
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack18 Feb 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2023-4911HIGHunder attack18 Feb 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack18 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL17 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack17 Feb 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1881816 Feb 2025
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-24016CRITICALunder attack16 Feb 2025
Remote code execution in Wazuh server
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL14 Feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-0108HIGHunder attack14 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL14 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware14 Feb 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware14 Feb 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack13 Feb 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
VulnCheck XDB
initial-access
CVE-2025-0108HIGHunder attack13 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL13 Feb 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALunder attack13 Feb 2025
Remote code execution in Wazuh server
100RISK
open
VulnCheck XDB
client-side
CVE-2024-42009CRITICALunder attack13 Feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack12 Feb 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH12 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack12 Feb 2025
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware12 Feb 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.