Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,646cataloged exploits
37,382CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,825GitHub PoC 15,392VulnCheck XDB 9,029Nuclei 4,416Metasploit 3,502✓ verified onlyrecentpopularrisk
80,646 exploits
VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 10
A simple PoC demonstrating the vulnerability in the ThrottleStop.sys driver, showcasing arbitrary physical memory read and write capabilities, as well as virtual-to-physical address translation using Superfetch.
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open ↗VulnCheck XDB
initial-access
SolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
78RISK
open ↗GitHub PoC★ 1
Local Priviledge Escalation for Druva
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RISK
open ↗VulnCheck XDB
initial-access
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open ↗VulnCheck XDB
initial-access
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗Metasploit300
osTicket Arbitrary File Read via PHP Filter Chains in mPDF
osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read
58RISK
open ↗GitHub PoC
Unauthenticated file upload for Chamilo 1.11.24 and lower
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open ↗VulnCheck XDB
denial-of-service
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISK
open ↗VulnCheck XDB
info-leak
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open ↗GitHub PoC
0x13-ByteZer0/CVE-2024-21762
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open ↗VulnCheck XDB
initial-access
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RISK
open ↗GitHub PoC
POC for the CVE-2025-32462 and CVE-2025-32463 vulnerabilities
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open ↗GitHub PoC★ 100
Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open ↗GitHub PoC★ 2
alexcyberx/CVE-2025-14847_Expolit
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 2
CVE-2025-14847 | MongoBleed vulnerability proof of concept project
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RISK
open ↗GitHub PoC★ 3
CVE-2025-52694 Critical SQL Injection in Advantech IoTSuite/SaaS-Composer
Execution of arbitrary SQL commands
75RISK
open ↗VulnCheck XDB
initial-access
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
React2Shell is a high-performance vulnerability scanner written in Go, specifically designed to detect Server-Side Remote Code Execution (RCE) vulnerabilities in Next.js applications (CVE-2025-55182 & CVE-2025-66478).
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
initial-access
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open ↗GitHub PoC★ 1
CVE-2026-22241 Exploit for GUnet Open eClass Unrestricted File Upload Leads to Remote Code Execution (RCE)
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
41RISK
open ↗GitHub PoC
Technical analysis and reproduction lab for the Apache HTTP Server 2.4.49 Path Traversal and RCE vulnerability.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open ↗GitHub PoC★ 3
Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗GitHub PoC
Mr-In4inci3le/CVE-2025-11953-POC-
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
100RISK
open ↗GitHub PoC★ 1
Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.
Path traversal vulnerability in WinRAR
93RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.