Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,753cataloged exploits
37,445CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,871GitHub PoC 15,407VulnCheck XDB 9,065Nuclei 4,426Metasploit 3,502✓ verified onlyrecentpopularrisk
80,753 exploits
VulnCheck XDB
initial-access
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗VulnCheck XDB
infoleak
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
75RISK
open ↗VulnCheck XDB
initial-access
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open ↗Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
AVideo < 20.1 User Information Disclosure via Public API
28RISK
open ↗Metasploit300
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 3
React2Shell vulnerability (CVE-2025-55182 / CVE-2025-66478) Full Script
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
open-flaw/CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt
63RISK
open ↗Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
AVideo < 20.1 System Path Disclosure via Public API
28RISK
open ↗GitHub PoC
PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain, featuring optional proxy support, automated session elevation, and dynamic command injection via the print scripting engine. Designed for security auditing and authorized penetration testing.
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open ↗GitHub PoC★ 6
PoC for CVE-2025-37164
A remote code execution issue exists in HPE OneView.
100RISK
open ↗GitHub PoC★ 16
Detection for CVE-2025-68461
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RISK
open ↗GitHub PoC★ 1
lamaper/CVE-2025-55182-Toolbox
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
Control Web Panel <= 0.9.8.1208 (admin/index.php) OS Command Injection Vulnerability • Software Link:
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /
56RISK
open ↗GitHub PoC★ 4
React2Shell (CVE-2025-66478): A Python-based Proof of Concept for Critical Remote Code Execution (RCE) in Next.js Server Components. Features an interactive CLI, custom payload injection, and cleaner output formatting. For educational research only.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
1C-Bitrix <= 25.100.500 (Translate Module) Remote Code Execution Vulnerability
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla
48RISK
open ↗GitHub PoC★ 3
Fox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder'
Fox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder'
48RISK
open ↗GitHub PoC
rashedhasan090/cve-2025-55182-mitigator
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 1
CVE-2025-40602 is a local privilege escalation vulnerability in the appliance management console (AMC) of SonicWall Secure Mobile Access (SMA) 1000 series appliances.
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RISK
open ↗GitHub PoC★ 3
Detection for CVE-2025-40602
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RISK
open ↗GitHub PoC
Bitrix24 <= 25.100.300 (Translate Module) Remote Code Execution Vulnerability
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat
33RISK
open ↗GitHub PoC
cyberok-org/CVE-2025-67887
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla
48RISK
open ↗GitHub PoC
POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on hands-on exploitation steps, reproducible test cases, and observable impact, helping security researchers and defenders understand the issue and validate fixes.
Internet Shortcut Files Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 22
Script to detect CVE-2025-20393 for Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open ↗GitHub PoC
KingHacker353/CVE-2025-20393
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open ↗GitHub PoC★ 2
Cisco is aware of a potential vulnerability. Cisco is currently investigating and will update these details as appropriate as more information becomes available.
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open ↗GitHub PoC
React2Shell Vulnerability Verification Script (React2Shell also known as CVE-2025-55182).
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 9
Proof-of-Concept exploit for CVE-2025-14174 (EUVD-2025-203113) - Memory corruption in ANGLE allowing out-of-bounds access and RCE in web browsers. Reliable on iOS/Android/Windows, including patched systems with incomplete fixes.
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISK
open ↗GitHub PoC
Proof of Concept for Authenticated RCE in Crafty Controller
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.