Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,521GitHub PoC 15,321VulnCheck XDB 8,970Nuclei 4,394Metasploit 3,502✓ verified onlyrecentpopularrisk
80,184 exploits
GitHub PoC★ 1
Scan your NGINX configuration to determine whether it is affected by CVE-2026-42945.
NGINX ngx_http_rewrite_module vulnerability
60RISK
open ↗GitHub PoC
Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd 2.3.4 backdoor (CVE-2011-2523).
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗GitHub PoC★ 15
p3Nt3st3r-sTAr/CVE-2026-42945-POC
NGINX ngx_http_rewrite_module vulnerability
60RISK
open ↗GitHub PoC
These detection scripts are property of the SECPlayground Platform. Two safe detection scripts. Neither drives the close_notify-mid-BDAT trigger, so they will not crash the daemon or leave panic-log entries. Both verdicts are "likely vulnerable" — distinguishing GnuTLS from OpenSSL builds remotely is not reliable without exploitation.
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p
48RISK
open ↗VulnCheck XDB
denial-of-service
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open ↗VulnCheck XDB
initial-access
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open ↗GitHub PoC★ 2
CVE-2011-3192 - Remote Apache DOS for Apache versions 1.3.x, 2.0.64 and below and 2.2.19 and below. Developed in 2011 by Antonius (ev1lut10n / w1sdom)
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISK
open ↗GitHub PoC★ 2
CVE-2005-0575 - KNet Web Server 1.04b Remote Buffer Overflow SEH Exploit for x86 Windows XP SP3, this exploit needs some adjustment ! edit the code before run ! Developed by Antonius - made in the past, I forgot when I made it
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RISK
open ↗GitHub PoC
User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter
User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter
33RISK
open ↗GitHub PoC
ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945
NGINX ngx_http_rewrite_module vulnerability
60RISK
open ↗GitHub PoC
ydking0911/CVE-2026-4060-PoC
Geo Mashup <= 1.13.18 - Unauthenticated Time-Based SQL Injection via 'sort' Parameter
56RISK
open ↗GitHub PoC★ 2
nanwinata/nginxrift-CVE-2026-42945
NGINX ngx_http_rewrite_module vulnerability
60RISK
open ↗GitHub PoC★ 1
CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit
Wing FTP Server < 8.1.3 Authenticated Remote Code Execution via Session Serialization
41RISK
open ↗GitHub PoC★ 5
CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open ↗GitHub PoC★ 1
Proof of concept exploit for CVE-2026-46391
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
41RISK
open ↗Metasploit500
Fragnesia LPE (CVE-2026-46300)
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open ↗Metasploit300
Linux Kernel __ptrace_may_access() Exit Race chage File Disclosure
ptrace: slightly saner 'get_dumpable()' logic
56RISK
open ↗GitHub PoC
A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open ↗Exploit-DB
Flowise < 3.0.5 - Missing Authentication for Critical Function
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISK
open ↗GitHub PoC
copy-fail-CVE-2026-31431
crypto: algif_aead - Revert to operating out-of-place
100RISK
open ↗GitHub PoC
Bencodin/CVE-2026-23918-poc
Apache HTTP Server: http2: double free and possible RCE on early reset
53RISK
open ↗GitHub PoC★ 2
Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts, and attacker commits. Python, Bash, PowerShell.
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RISK
open ↗GitHub PoC
There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters passed in from the command line. Attackers can read any readable file by constructing malicious paths, posing a risk of information leakage.
A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program com
33RISK
open ↗GitHub PoC
OOB verifier for GHSA-c4j6-fc7j-m34r / CVE-2026-44578 (Next.js WebSocket-upgrade SSRF)
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open ↗GitHub PoC★ 260
Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.