Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
13,307 exploits
GitHub PoC★ 1
PoC for CVE-2025-2011 - SQLi in Depicter plugin <= 3.6.1
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open ↗GitHub PoC★ 1
Commvault Remote Code Execution (CVE-2025-34028) NSE
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗GitHub PoC
Shellshock Vulnerability Scanner
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC★ 1
CVE-2025-4524 - Unauthenticated madara-core Wordpress theme LFI
Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion
63RISK
open ↗GitHub PoC★ 1
Scanner and exploit for CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗GitHub PoC★ 1
ductink98lhp/analyze-Exploit-CVE-2023-22518-Confluence
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open ↗GitHub PoC★ 5
This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions and upload malicious files. This can lead to Remote Code Execution (RCE) when the uploaded payload is triggered.
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through
48RISK
open ↗GitHub PoC★ 2
Artemir7/CVE-2025-24893-EXP
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗GitHub PoC
CCIEVoice2009/CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗GitHub PoC
Bridg3Ops/SOC335-CVE-2024-49138-Exploitation-Detected
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open ↗GitHub PoC
This CVE - PoC about information on the CVEs I found.
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
33RISK
open ↗GitHub PoC
Vite Development Server's @fs endpoint (CVE-2025-31125) to access sensitive files like /etc/passwd and /etc/hosts via crafted URLs.
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISK
open ↗GitHub PoC★ 3
This repository includes everything needed to run a PoC exploit for CVE-2025-32375 in a Docker environment. It runs the latest vulnerable version of BentoML (1.4.7).
Insecure Deserialization leads to RCE in BentoML's runner server
75RISK
open ↗GitHub PoC★ 1
olimpiofreitas/CVE-2025-29927-scanner
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code execution. One malformed SSH handshake bypasses authentication and exploits improper handling of SSH protocol messages.
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open ↗GitHub PoC★ 1
ByteMe1001/CVE-2020-13151-POC-Aerospike-Server-Host-Command-Execution-RCE-
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RISK
open ↗GitHub PoC
CVE-2024-10914 Shell Exploit
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open ↗GitHub PoC★ 1
CVE-2016-5195 linux kernel exploit
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC
katseyres2/CVE-2022-44268-pilgrimage
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open ↗GitHub PoC
Simple PoC of wpstorecart before 2.5.30 plugin exploit (CVE-2012-3576) written in bash.
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re
28RISK
open ↗GitHub PoC
toothbrushsoapflannelbiscuits/cve-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC
This python scripts searches a client list to see if their FortiGate device is vulnerable to this CVE.
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open ↗GitHub PoC★ 1
CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open ↗GitHub PoC
sattarbug/Analysis-of-TomcatKiller---CVE-2025-31650-Exploit-Tool
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISK
open ↗GitHub PoC★ 1
CVE-2024-27956 - WP Automatic SQL Injection Exploit Tool
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC★ 9
CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗GitHub PoC★ 2
CVE-2025-31650 PoC
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISK
open ↗GitHub PoC★ 2
本脚本是针对 GeoServer 的远程代码执行漏洞(CVE-2024-36401)开发的 PoC(Proof of Concept)探测工具。该漏洞允许攻击者通过构造特定请求,在目标服务器上执行任意命令。
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open ↗GitHub PoC★ 20
A tool designed to detect the vulnerability **CVE-2025-31650** in Apache Tomcat (versions 10.1.10 to 10.1.39)
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.