Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,614GitHub PoC 15,330VulnCheck XDB 9,001Nuclei 4,401Metasploit 3,502✓ verified onlyrecentpopularrisk
80,324 exploits
GitHub PoC
Penetration test report for MegaQuagga Publishing documenting a six-phase engagement that chained CVE-2019-9978 and CVE-2023-4842 to achieve unauthenticated Remote Code Execution and a persistent Meterpreter session. Includes full methodology, exploitation evidence, and prioritized remediation recommendations.
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open ↗GitHub PoC
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
41RISK
open ↗Exploit-DB
Windows 11 23H2 - Denial of Service (DoS)
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
Winrar Exploit CVE-2023-38831
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open ↗Exploit-DB
SUSE Manager 4.3.15 - Code Execution
SUSE Multi Linux Manager allows code execution via unprotected websocket endpoint
53RISK
open ↗GitHub PoC★ 14
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclosed 2026-04-28. Defense-in-depth active mitigation shim, ModSec rule pack, remote probe, on-host IOC scanner, and per-tier RE snapshot collector. GPL v2.
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open ↗Exploit-DB
Python-Multipart 0.0.22 - Path Traversal
Python-Multipart has Arbitrary File Write via Non-Default Configuration
41RISK
open ↗Exploit-DB
SumatraPDF 3.5.2 - Remote Code Execution
SumatraPDF Update MITM -> Arbitrary Code Execution
41RISK
open ↗Exploit-DB
Frigate NVR 0.16.3 - Remote Code Execution
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.