Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,624GitHub PoC 13,727VulnCheck XDB 8,410Nuclei 4,231Metasploit 3,467✓ verified onlyrecentpopularrisk
75,655 exploits
GitHub PoC★ 11
CVE-2025-6018 Poc and Exploit
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open ↗GitHub PoC★ 2
Fineken/Jenkins-CVE-2024-23897-Lab
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗GitHub PoC★ 4
This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious `CIF` file to the hosted `CIF Analyzer` website on the target running on the Chemistry machine from Hack the Box.
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open ↗GitHub PoC★ 8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open ↗GitHub PoC★ 4
How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RISK
open ↗VulnCheck XDB
infoleak
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
denial-of-service
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open ↗GitHub PoC
A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over testing parameters, multiple attack patterns, and advanced monitoring capabilities.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗GitHub PoC
shan0ar/cve-2025-32756
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open ↗VulnCheck XDB
infoleak
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00
35RISK
open ↗GitHub PoC
Proof-of-concept LFI Scanner: Automated detection of /etc/passwd exposures via directory traversal and regex matching.
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RISK
open ↗GitHub PoC★ 1
WordPress联系表单插件 - 未授权任意文件上传漏洞
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RISK
open ↗GitHub PoC★ 31
Integer overflow in FreeType software, which also affects Chrome
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RISK
open ↗GitHub PoC
wyyazjjl/CVE-2024-45195
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
100RISK
open ↗GitHub PoC★ 1
Nuclei template to detect CVE-2024-6387. All latest patched versions are excluded.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC★ 1
PoC exploit for CVE-2025-7766 – XXE vulnerability leading to potential RCE.
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RISK
open ↗VulnCheck XDB
client-side
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside
83RISK
open ↗GitHub PoC
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 5
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition)
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 4
PoC for CVE-2025-5777 – Auth Bypass and RCE in Trend Micro Apex Central
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open ↗VulnCheck XDB
initial-access
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open ↗GitHub PoC★ 8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.