Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,614GitHub PoC 15,330VulnCheck XDB 9,001Nuclei 4,401Metasploit 3,502✓ verified onlyrecentpopularrisk
80,324 exploits
Exploit-DB
Throttlestop Kernel Driver - Kernel Out-of-Bounds Write Privilege Escalation
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open ↗GitHub PoC★ 1
Analysis and exploit for CVE-2026-25250, a Secure Boot bypass in Horizon DataSys Reboot Restore where shdloader.efi loads Shield.efi without verification.
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot
33RISK
open ↗Exploit-DB
WordPress Plugin 5.2.0 - Broken Access Control
WordPress Highlight and Share plugin <= 5.2.0 - Broken Access Control vulnerability
33RISK
open ↗GitHub PoC
CVE-2019-15107 Webmin RCE (unauthenticated) exploit
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open ↗GitHub PoC★ 4
Full exploit for the Android vulnerability Bad Binder found in early Google Pixel phones.
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗GitHub PoC
Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗VulnCheck XDB
initial-access
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open ↗Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
Xerte Online Toolkits File Upload RCE via elfinder Connector
63RISK
open ↗Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
Xerte Online Toolkits Missing Authentication via connector.php
56RISK
open ↗GitHub PoC★ 1
End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock (CVE-2014-6271).
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
Xerte Online Toolkits Path Traversal via connector.php
56RISK
open ↗GitHub PoC
CVEs-Labs/CVE-2026-21876
OWASP CRS has multipart bypass using multiple content-type parts
53RISK
open ↗Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
Xerte Online Toolkits Path Disclosure via /setup
48RISK
open ↗GitHub PoC
jpselva/CVE-2023-4863
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open ↗GitHub PoC★ 1
(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)
Ghost Vulnerable to Remote Code Execution via Malicious Themes
56RISK
open ↗GitHub PoC
ClaraSto/CVE-2024-1086_Ausarbeitung
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open ↗GitHub PoC
Qualitative TVRA for a multi-VLAN enterprise lab: Stored XSS on WebGoat (HIGH, 16), Stored XSS on Magento (ABSENT, MEDIUM, 8), and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25). Scored via Likelihood × Impact using CVSS v3.0 and ZAP/Nessus/Wireshark evidence.
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗Metasploit300
BerriAI LiteLLM Proxy Pre-Auth SQL Injection Scanner
LiteLLM: SQL injection in Proxy API key verification
100RISK
open ↗GitHub PoC★ 1
The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO).
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISK
open ↗GitHub PoC
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
33RISK
open ↗GitHub PoC
We hope to reproduce CVE-2021-41773 to deepen our understanding of real-world cybersecurity vulnerabilities so that we can be knowledgeable about exploits in industry and academic work.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open ↗GitHub PoC
Multi-VLAN virtual network across 10 VMs: GRE tunneling, nftables firewall, Active Directory, BIND9 DNS, Kea DHCP, Docker web services, SMB file sharing. Vulnerability assessment using OWASP ZAP (Stored XSS) and Nessus (CVE-2017-0144 EternalBlue). Validated with Wireshark.
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗GitHub PoC★ 1
wa6n3r/CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open ↗VulnCheck XDB
info-leak
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RISK
open ↗GitHub PoC★ 83
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open ↗VulnCheck XDB
initial-access
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open ↗GitHub PoC
Type Local Privilege Escalation exploit for CVE-2021-3493(Ubuntu Kernel vulnerability) documrnted during TryHackme Lab
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.