Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
13,334 exploits
GitHub PoC★ 3
WP Load Gallery <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
WordPress WP Load Gallery Plugin <= 2.1.6 - Arbitrary File Upload vulnerability
48RISK
open ↗GitHub PoC
Code to exploit CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗GitHub PoC★ 4
numanturle/CVE-2025-25279
Arbitrary file read in Mattermost Boards via import & export board archive
53RISK
open ↗GitHub PoC★ 1
Copy of the POC for CVE-2023-1545
SQL Injection in nilsteampassnet/teampass
41RISK
open ↗GitHub PoC★ 3
shishirghimir/CVE-2024-53677-Exploit
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open ↗GitHub PoC
vivigotnotime/CVE-2023-22515-Exploit-Script
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗GitHub PoC★ 1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open ↗GitHub PoC★ 2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open ↗GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
WinVerifyTrust Signature Validation Vulnerability
75RISK
open ↗GitHub PoC
Example usage: exploit.sh http://site.com
SQL Injection in nilsteampassnet/teampass
41RISK
open ↗GitHub PoC★ 4
CVE-2023-1698 Proof of Concept (PoC)
WAGO: WBM Command Injection in multiple products
85RISK
open ↗GitHub PoC★ 1
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
Remote code execution in Wazuh server
100RISK
open ↗GitHub PoC
CVE-2025-24971 exploit
OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop
48RISK
open ↗GitHub PoC★ 5
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
Remote code execution in Wazuh server
100RISK
open ↗GitHub PoC★ 2
PoC of the vulnerability CVE-2024-23346
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open ↗GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
PrestaShop vulnerable to XSS via customer contact form in FO, through file upload
60RISK
open ↗GitHub PoC★ 1
ishwardeepp/CVE-2025-0411-MoTW-PoC
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open ↗GitHub PoC
Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗GitHub PoC
A fully functional exploit for a stack-based buffer overflow vulnerability in VideoLan’s VLC Media Player 0.9.4 when processing TiVo files.
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISK
open ↗GitHub PoC
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrar
33RISK
open ↗GitHub PoC
barcrange/CVE-2025-0108-Authentication-Bypass-checker
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open ↗GitHub PoC★ 1
PAN-OS CVE POC SCRIPT
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open ↗GitHub PoC★ 2
NSE script that checks for CVE-2025-0108 vulnerability in Palo Alto Networks PAN-OS
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open ↗GitHub PoC
POC for CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗GitHub PoC★ 13
Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RISK
open ↗GitHub PoC★ 2
Detects an authentication bypass vulnerability in Palo Alto PAN-OS (CVE-2025-0108).
PAN-OS: Authentication Bypass in the Management Web Interface
100RISK
open ↗GitHub PoC
Exploitation Script for CVE-2021-3560
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗GitHub PoC
CVE-2023-4911-Looney-Tunables
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.