Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,973GitHub PoC 15,478VulnCheck XDB 9,069Nuclei 4,426Metasploit 3,502✓ verified onlyrecentpopularrisk
80,930 exploits
VulnCheck XDB
initial-access
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC★ 1
Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗GitHub PoC
Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)
Grafana SQL Expressions allow for remote code execution
85RISK
open ↗GitHub PoC
CVE-2025-48384-submodule
Git allows arbitrary code execution through broken config quoting
71RISK
open ↗GitHub PoC★ 7
Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISK
open ↗GitHub PoC
chin-tech/CrushFTP_CVE-2025-54309
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open ↗GitHub PoC
GIT vulnerability | Carriage Return and RCE on cloning
Git allows arbitrary code execution through broken config quoting
71RISK
open ↗GitHub PoC★ 4
Ash1996x/CVE-2025-54914-PoC
Azure Networking Elevation of Privilege Vulnerability
48RISK
open ↗GitHub PoC
Grafana CVE-2025-4123-POC
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open ↗VulnCheck XDB
infoleak
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗GitHub PoC★ 8
FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗VulnCheck XDB
client-side
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open ↗GitHub PoC★ 2
CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain attack affecting Linux systems, highlighting risks in trusted open-source components.
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 1
JinhyukKo/CVE-2024-4701-POC
Path Traversal vulnerability via File Uploads in Genie
53RISK
open ↗GitHub PoC
This repository contains **research and analysis** related to CVE-2025-29927. It demonstrates safe, controlled testing approaches for a path traversal/middleware misconfiguration vulnerability in web applications.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
Detection for CVE-2025-42944
Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)
48RISK
open ↗VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
initial-access
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open ↗GitHub PoC★ 1
In-depth study of CVE-2019-18935 affecting Telerik UI for ASP.NET AJAX. Covers .NET deserialization vulnerability, RadAsyncUpload handler, gadget chains, mixed-mode assembly exploitation, and mitigation strategies.
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open ↗GitHub PoC★ 1
For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗GitHub PoC
exploit of CVE-2022-0847 which directly remove password of the root account
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC
A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demos
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC
Zuack55/Roundcube-1.6.10-Post-Auth-RCE-CVE-2025-49113-
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open ↗GitHub PoC
Linux privilege escalation using Dirty COW exploit (CVE-2016-5195).
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗GitHub PoC★ 4
CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full control. The article explains the vulnerability, threat model, provides minimal exploit ABAP code, and lists patching & monitoring steps to secure the system
Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
48RISK
open ↗VulnCheck XDB
local
Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
48RISK
open ↗VulnCheck XDB
infoleak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.