Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,646cataloged exploits
37,382CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,825GitHub PoC 15,392VulnCheck XDB 9,029Nuclei 4,416Metasploit 3,502✓ verified onlyrecentpopularrisk
80,646 exploits
GitHub PoC
Authenticated RCE for Webmin 1.9.0
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
43RISK
open ↗GitHub PoC★ 24
CVE-2025-68428 Proof of Concept
jsPDF has Local File Inclusion/Path Traversal vulnerability
48RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
alxsourin/Helpdesk-Telecom-CVE-2025-64459
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open ↗GitHub PoC★ 1
flame-11/CVE-2025-54068-livewire
Livewire vulnerable to remote command execution during property update hydration
100RISK
open ↗GitHub PoC
Auto exploitation tool for CVE-2024-24401
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payl
60RISK
open ↗GitHub PoC
CVE-2025-14847 PoC exploit for MongoDB heap memory disclosure
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 31
CVE-2025-55182-bypass-waf
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 1
Full automation check for CVE-2025-14847 MonogBleed- Finds origin IP and tests for exploit.
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 22
CVE-2025-60188 Atarim Plugin Exploit
WordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
56RISK
open ↗GitHub PoC
analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open ↗VulnCheck XDB
initial-access
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open ↗GitHub PoC★ 1
CVE-2022-0847(Linux 内核本地提权漏洞)
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗VulnCheck XDB
remote-with-credentials
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗GitHub PoC★ 1
在python3中运行的脚本
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open ↗GitHub PoC
analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open ↗GitHub PoC
CVE-2025-55182-poc-json
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
ingress-nginx admission controller RCE escalation PoC
ingress-nginx admission controller RCE escalation
85RISK
open ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC★ 1
Mass Exploit for CVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open ↗GitHub PoC
"Once upon a time, the Castle of Reactland trusted all Flight messages... until The Imposter arrived." A storytelling CVE-2025-55182 (React2Shell) demo - Medieval-themed vulnerable React Server Components app for security education.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
initial-access
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 1
CVE-2025-14847 MongoDB Memory Leak Exploit
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
CVE-2025-55182, also known as React2Shell, is a critical vulnerability affecting Next.js applications using React Server Components (RSC) and Server Actions.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.