Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
75,589 exploits
GitHub PoC
shoucheng3/xwiki__xwiki-rendering_CVE-2023-37908_14-10-3
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
48RISK
open ↗GitHub PoC
shoucheng3/apache__shiro_CVE-2023-34478_1-11-0
Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests.
48RISK
open ↗GitHub PoC
Research Objective: To conduct a comprehensive analysis and successful exploitation of a Remote Code Execution (RCE) vulnerability in Webmin version 1.890 (CVE-2019-15107), ultimately gaining full control over the target system.
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗VulnCheck XDB
infoleak
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open ↗GitHub PoC★ 5
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open ↗GitHub PoC★ 36
Exploit systems using older WinRAR without knowing their username (unlike other projects)
Path traversal vulnerability in WinRAR
93RISK
open ↗GitHub PoC★ 1
Exploit for CVE-2018-7422: Local File Inclusion in WordPress Plugin Site Editor 1.1.1 [T1574.008]
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open ↗GitHub PoC
shoucheng3/apache__myfaces_CVE-2011-4367_2-0-11
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.1
35RISK
open ↗GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISK
open ↗VulnCheck XDB
initial-access
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗GitHub PoC★ 110
PoC and technical details of CVE-2025-24204
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access pr
48RISK
open ↗GitHub PoC★ 4
Safe Python script to detect Cisco FMC instances potentially vulnerable to CVE-2025-20265. Uses official FMC API to check version, supports single/multi-target scanning, and includes a harmless local PoC marker.
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RISK
open ↗GitHub PoC★ 1
0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC
Path traversal vulnerability in WinRAR
93RISK
open ↗VulnCheck XDB
initial-access
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
75RISK
open ↗GitHub PoC★ 1
0xr2r/CVE-2017-11317-auto-exploit-
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open ↗GitHub PoC
hlc23/CVE-2024-5932-web-ui
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open ↗GitHub PoC★ 22
sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗GitHub PoC★ 2
MailPoet Newsletters <= Arbitrary File Upload (exploiter)
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen
50RISK
open ↗VulnCheck XDB
initial-access
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen
50RISK
open ↗GitHub PoC★ 4
A PoC for CVE-2024-3660. Arbitrary Code Execution in Keras.
Arbitrary code injection vulnerability in Keras framework < 2.13
48RISK
open ↗Metasploit600
Flowise Custom MCP Remote Code Execution
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
65RISK
open ↗GitHub PoC
Kento-Sec/CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
n0m-d/CVE-2018-0114-Go
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open ↗VulnCheck XDB
infoleak
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that
100RISK
open ↗GitHub PoC★ 56
Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088
Path traversal vulnerability in WinRAR
93RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.