Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,692GitHub PoC 13,812VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
76,008 exploits
VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗VulnCheck XDB
initial-access
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISK
open ↗VulnCheck XDB
initial-access
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open ↗VulnCheck XDB
initial-access
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open ↗VulnCheck XDB
initial-access
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISK
open ↗GitHub PoC★ 12
Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 24
CVE-2025-31324, SAP Exploit
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗VulnCheck XDB
remote-with-credentials
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open ↗VulnCheck XDB
initial-access
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗GitHub PoC★ 2
CVE-2022-3552 RCE with detailed exploitation steps
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISK
open ↗GitHub PoC
airtiels 5650 CVE-2015-2797 PoC
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RISK
open ↗GitHub PoC★ 1
yeahhbean/Laravel-CVE-2018-15133
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open ↗GitHub PoC
romanedutov/CVE-2025-2294
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open ↗GitHub PoC★ 10
CraftCMS RCE Checker (CVE-2025-32432)
Craft CMS Allows Remote Code Execution
100RISK
open ↗GitHub PoC★ 2
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open ↗VulnCheck XDB
infoleak
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open ↗GitHub PoC
ChoDeokCheol/CVE-2023-39361
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISK
open ↗VulnCheck XDB
initial-access
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISK
open ↗VulnCheck XDB
client-side
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
initial-access
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open ↗GitHub PoC★ 4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.