Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,842cataloged exploits
37,493CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,901GitHub PoC 15,465VulnCheck XDB 9,066Nuclei 4,426Metasploit 3,502✓ verified onlyrecentpopularrisk
80,842 exploits
GitHub PoC★ 3
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open ↗GitHub PoC
CaelumIsMe/CVE-2019-9053-POC
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗GitHub PoC
We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered msdt.exe execution, suggesting possible remote code execution on the host JonasPRD. Our task is to investigate the alert, confirm exploitation, assess impact, and recommend remediation.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC
Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics, Web Exploitation (SQLi, XSS), Cryptography, and Kernel Exploitation (OverlayFS/CVE-2015-1328) to achieve full root compromise.
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open ↗GitHub PoC★ 7
Privilege escalation in Fedora Linux via ABRT (Automatic Bug Reporting Tool): CVE-2025-12744
Abrt: command-injection in abrt leading to local privilege escalation
41RISK
open ↗VulnCheck XDB
infoleak
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC★ 1
Sudo Vulnerability Local PrivEsc (CVE-2025-32463) POC with Python
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC★ 1
Yukik4z3/CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC
0axz-tools/CVE-2024-51793
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISK
open ↗GitHub PoC
CVE-2017-1000367
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISK
open ↗GitHub PoC★ 1
secvulnhub/CVE-2025-32463-EXPLOIT
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC
CVE-2024-27956
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗GitHub PoC★ 1
Sudo Vulnerability Local PrivEsc (CVE-2025-32463) POC with Python
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗VulnCheck XDB
local
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISK
open ↗GitHub PoC
autocode07/cisagov__check-cve-2019-19781.4142e02b
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open ↗GitHub PoC
POC of CVE-2025-61882
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open ↗VulnCheck XDB
client-side
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RISK
open ↗GitHub PoC
PoC of CVE-2025-60751
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
41RISK
open ↗GitHub PoC★ 1
The default configuration of LDAP on FortiOS v6.0.x to v6.2.0 does not check server identity for LDAP/S leading to MITM attacks. This PoC demos full exfiltration of credentials sent on the local subnet to an LDAP server that is easily impersonated.
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept s
83RISK
open ↗GitHub PoC★ 1
Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources, and mitigations (parity checks, attestations, or SBOMs, as well as SLSA)
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 46
Tool that reproduces CVE-2025-55315 in ASP.NET Core.
ASP.NET Security Feature Bypass Vulnerability
60RISK
open ↗GitHub PoC★ 7
Playground to experiment with different behavior on patched/unpatched Kestrel for the CVE-2025-55315 HTTP smuggling vulnerability
ASP.NET Security Feature Bypass Vulnerability
60RISK
open ↗GitHub PoC★ 13
Proof of concept for CVE-2022-1364 against Alibaba's UC Browser
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.