Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
13,334 exploits
GitHub PoC★ 48
全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗GitHub PoC★ 250
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISK
open ↗GitHub PoC★ 97
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
ingress-nginx admission controller RCE escalation
85RISK
open ↗GitHub PoC
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
ingress-nginx admission controller RCE escalation
85RISK
open ↗GitHub PoC★ 4
PoC of CVE-2025-1974, modified from the world-first PoC~
ingress-nginx admission controller RCE escalation
85RISK
open ↗GitHub PoC★ 1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
ingress-nginx admission controller RCE escalation
85RISK
open ↗GitHub PoC
CVE-2025-22912
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RISK
open ↗GitHub PoC
Check if a username is valid on the SSH server by attempting an authentication. The server response will indicate whether the username exists.
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open ↗GitHub PoC★ 2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
Azure Storage Resource Provider Spoofing Vulnerability
48RISK
open ↗GitHub PoC
Critical vulnerability in next.js : Bypass middleware authentication
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 9
Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 5
PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 2
PowerShell script to test if a web app is vulnerable to CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 3
script to check cve "CVE-2025-29927" while waiting to add it to HExHTTP
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
maronnjapan/claude-create-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
somatrasss/CVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open ↗GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RISK
open ↗GitHub PoC★ 1
POC for CVE-2023-30258-RCE by n0o0b
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open ↗GitHub PoC
The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
A root exploit for CVE-2022-0847 (Dirty Pipe)
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.