Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
client-side
CVE-2024-42009CRITICALunder attack11 Feb 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack11 Feb 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53704HIGHunder attackransomware11 Feb 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL11 Feb 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-3864610 Feb 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-27348CRITICALunder attack10 Feb 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-0847HIGHunder attack09 Feb 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack08 Feb 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-39713HIGH07 Feb 2025
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
56RISK
open
VulnCheck XDB
client-side
CVE-2022-30190HIGHunder attackransomware07 Feb 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware06 Feb 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-20085HIGHunder attack06 Feb 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware06 Feb 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware05 Feb 2025
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL05 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL05 Feb 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH04 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH02 Feb 2025
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware02 Feb 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-26319CRITICAL02 Feb 2025
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware02 Feb 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware02 Feb 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL02 Feb 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2014-370402 Feb 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-023231 Jan 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-33891HIGHunder attack30 Jan 2025
Apache Spark shell command injection vulnerability via Spark UI
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-0235MEDIUM30 Jan 2025
EventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-32315HIGHunder attack30 Jan 2025
Openfire administration console authentication bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware30 Jan 2025
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-36804HIGHunder attack30 Jan 2025
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.