Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
13,689 exploits
GitHub PoC
NanoWraith/CVE-2024-5084
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open ↗GitHub PoC
WanLiChangChengWanLiChang/CVE-2024-25600
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗GitHub PoC
NanoWraith/CVE-2024-25600
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗GitHub PoC★ 4
conan-sudo/CVE-2019-14974-bypass
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
50RISK
open ↗GitHub PoC
A script to exploit CVE-2020-1472 (Zerologon)
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 26
Sk1dr0wz/CVE-2024-4358_Mass_Exploit
Registration Authentication Bypass Vulnerability
100RISK
open ↗GitHub PoC★ 1
Oracle WebLogic Server (LFI)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open ↗GitHub PoC
This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps.
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗GitHub PoC★ 9
CVE-2024-4956 Python exploitation utility
Nexus Repository 3 - Path Traversal
61RISK
open ↗GitHub PoC
CVE-2021-1675/CVE-2021-34527 PrintNightmare & CVE-2020-0668
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open ↗GitHub PoC★ 5
An Vulnerability detection and Exploitation tool for CVE-2024-4358
Registration Authentication Bypass Vulnerability
100RISK
open ↗GitHub PoC★ 2
Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISK
open ↗GitHub PoC★ 1
muhammad1596/CVE-2022-0847-dirty-pipe-checker
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC★ 27
Apache OFBIZ Path traversal leading to RCE POC[CVE-2024-32113 & CVE-2024-36104]
Apache OFBiz: Path traversal leading to RCE
100RISK
open ↗GitHub PoC★ 1
New exploit for Apache APISIX v2.12.1 - Remote code execution (RCE)
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open ↗GitHub PoC★ 19
Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open ↗GitHub PoC★ 3
Sonatype Nexus Repository Manager 3 (LFI)
Nexus Repository 3 - Path Traversal
61RISK
open ↗GitHub PoC★ 2
kevcooper/CVE-2024-1086-checker
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open ↗GitHub PoC
Exploit created by nu11secur1ty (https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2022-37706)
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open ↗GitHub PoC★ 1
CVE-2023-51518: Preauthenticated Java Deserialization via JMX in Apache James
Apache James server: Privilege escalation via JMX pre-authentication deserialisation
48RISK
open ↗GitHub PoC★ 3
CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.
Information disclosure
100RISK
open ↗GitHub PoC★ 79
Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)
Registration Authentication Bypass Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.