Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 23,973GitHub PoC 15,478VulnCheck XDB 9,069Nuclei 4,426Metasploit 3,502✓ verified onlyrecentpopularrisk
80,930 exploits
Exploit-DB
Tenda AC20 16.03.08.12 - Command Injection
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RISK
open ↗GitHub PoC★ 1
The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python interpreter.
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗GitHub PoC★ 2
Proof of concept for CVE-2020-36708
Epsilon Framework Themes (Various Versions) - Function Injection
75RISK
open ↗Exploit-DB
Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure
Microsoft Windows File Explorer Spoofing Vulnerability
45RISK
open ↗GitHub PoC★ 3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISK
open ↗GitHub PoC★ 5
This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access dangerous classes like subprocess.Popen, leading to arbitrary command execution.
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open ↗VulnCheck XDB
initial-access
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISK
open ↗GitHub PoC
Demo of CVE-2025-29927 for secure programming class
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
Proof-of-Concept exploit script for Xdebug 2.5.5 and earlier versions (CVE-2015-10141).
Xdebug Remote Debugger Unauthenticated OS Command Execution
63RISK
open ↗GitHub PoC★ 2
Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)
Path traversal vulnerability in WinRAR
93RISK
open ↗GitHub PoC★ 3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISK
open ↗GitHub PoC★ 1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RISK
open ↗GitHub PoC
CVE-2019-12185 - eLabFTW 1.8.5 Python3 Exploit POC
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RISK
open ↗GitHub PoC★ 21
Detection for CVE-2025-8875 & CVE-2025-8876
Insecure Deserialization Vulnerability
78RISK
open ↗GitHub PoC
shoucheng3/spring-cloud__spring-cloud-config_CVE-2020-5410_2-1-8-RELEASE
Directory Traversal with spring-cloud-config-server
100RISK
open ↗GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open ↗GitHub PoC
shoucheng3/spring-projects__spring-security_CVE-2011-2732_2-0-6-RELEASE
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RISK
open ↗GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-37582_4-9-6
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISK
open ↗VulnCheck XDB
infoleak
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open ↗GitHub PoC★ 1
Exploit for CVE-2018-7422: Local File Inclusion in WordPress Plugin Site Editor 1.1.1 [T1574.008]
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open ↗GitHub PoC
shoucheng3/apache__myfaces_CVE-2011-4367_2-0-11
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.1
35RISK
open ↗GitHub PoC
shoucheng3/xwiki__xwiki-rendering_CVE-2023-37908_14-10-3
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
48RISK
open ↗GitHub PoC★ 1
Ash1996x/CVE-2025-50154-Aggressor-Script
Microsoft Windows File Explorer Spoofing Vulnerability
45RISK
open ↗GitHub PoC★ 36
Exploit systems using older WinRAR without knowing their username (unlike other projects)
Path traversal vulnerability in WinRAR
93RISK
open ↗GitHub PoC★ 5
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator accounts through the plugin’s insecure AJAX registration process.
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.