Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
13,334 exploits
GitHub PoC★ 25
Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open ↗GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISK
open ↗GitHub PoC★ 5
Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 3
Nuclei Template CVE-2025–24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC
KillReal01/CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open ↗GitHub PoC★ 1
Jimmy01240397/CVE-2024-12641_12642_12645
Chunghwa Telecom TenderDocTransfer - Reflected Cross-site Scripting to RCE
48RISK
open ↗GitHub PoC★ 1
regantemudo/CVE-2024-25641-Exploit-for-Cacti-1.2.26
Cacti RCE vulnerability when importing packages
85RISK
open ↗GitHub PoC★ 1
orilevy8/cve-2023-0386
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open ↗GitHub PoC
CVE-2024-9047, wfu_file_downloader.php
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISK
open ↗GitHub PoC
DavidBr27/CVE-2013-3900-Remediation-Script
WinVerifyTrust Signature Validation Vulnerability
75RISK
open ↗GitHub PoC★ 2
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open ↗GitHub PoC
RCE, Citirx ADC and Gateway Directory Traversal
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗GitHub PoC★ 403
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open ↗GitHub PoC★ 16
CVE-2025-24813利用工具
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 2
CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability
WordPress The Novel Design Store Directory plugin <= 4.3.0 - Arbitrary File Upload vulnerability
48RISK
open ↗GitHub PoC
ishwardeepp/CVE-2025-22604-Cacti-RCE
Cacti has Authenticated RCE via multi-line SNMP responses
48RISK
open ↗GitHub PoC★ 2
One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC
Webmin 1.580 /file/show.cgi Remote Code Execution
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open ↗GitHub PoC★ 1
User name enumeration against SSH daemons affected by CVE-2016-6210.
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISK
open ↗GitHub PoC
DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open ↗GitHub PoC
redpack-kr/CVE-2025-26319
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
75RISK
open ↗GitHub PoC
Pei4AN/CVE-2025-28915
WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability
48RISK
open ↗GitHub PoC★ 1
Security Researcher
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 3
CVE-2025-24813_POC
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 11
cve-2025-24813验证脚本
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 196
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 97
Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 1
HUSKY – Products Filter Professional for WooCommerce < 1.3.6.6 - Local File Inclusion PoC
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.