Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
76,107 exploits
GitHub PoC★ 2
sandsoncosta/CVE-2025-26633
Microsoft Management Console Security Feature Bypass Vulnerability
83RISK
open ↗VulnCheck XDB
initial-access
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open ↗Exploit-DB
InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut
48RISK
open ↗GitHub PoC
CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
pickovven/vulnerable-nextjs-14-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗VulnCheck XDB
denial-of-service
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISK
open ↗Exploit-DB
Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE)
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability
33RISK
open ↗Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re
23RISK
open ↗Exploit-DB
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISK
open ↗GitHub PoC★ 48
Proof of Concept for CVE-2025-31161 / CVE-2025-2825
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open ↗Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC
vances25/CVE-2024-44871
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISK
open ↗Exploit-DB
XWiki Platform 15.10.10 - Remote Code Execution
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗GitHub PoC
Heimd411/CVE-2025-24813-noPoC
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC
Hello researchers, I have a checker for the recent vulnerability CVE-2025-24813-checker.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC
DFG register allocation bug in JavaScriptCore
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
71RISK
open ↗GitHub PoC
Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 3
mouadk/parquet-rce-poc-CVE-2025-30065
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISK
open ↗Exploit-DB
YesWiki 4.5.1 - Unauthenticated Path Traversal
Path Traversal allowing arbitrary read of files in Yeswiki
56RISK
open ↗Exploit-DB
Apache Tomcat 11.0.3 - Remote Code Execution
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC
WHS 3기 장대혁 취약한(CVE) Docker 환경 구성 과제입니다.
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open ↗VulnCheck XDB
infoleak
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.