Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,003cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,011GitHub PoC 15,501VulnCheck XDB 9,077Nuclei 4,427Metasploit 3,505✓ verified onlyrecentpopularrisk
81,003 exploits
Exploit-DB
Xlight FTP 1.1 - Denial Of Service (DOS)
Xlightftpd Xlight FTP Server Login denial of service
33RISK
open ↗GitHub PoC★ 2
🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
The vulnerability was found by Rich Mirch. More details on it here: https://cxsecurity.com/issue/WLB-2025070022
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open ↗GitHub PoC★ 3
Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
68RISK
open ↗GitHub PoC
imbas007/CVE-2025-32429-Checker
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open ↗VulnCheck XDB
infoleak
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open ↗Exploit-DB
Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers
33RISK
open ↗GitHub PoC★ 1
🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
r3xbugbounty/CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 6
Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 2
A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.
macrozheng mall Swagger UI index.html cross site scripting
33RISK
open ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 2
Exploit for CVE-2022-35411 — Unauthenticated RCE in rpc.py (<= 0.6.0)
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISK
open ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
An activity to train analysis skills and reporting
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
QHxDr-dz/CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 15
CVE-2025-53770 Mass Scanner
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC★ 2
r0otk3r/CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗VulnCheck XDB
initial-access
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗GitHub PoC★ 3
This document describes a Denial of Service (DoS) vulnerability found in certain versions of MikroTik RouterOS. The vulnerability is due to insufficient handling of crafted SMB requests. A remote attacker could exploit this issue by sending a specially crafted request to the target server.
Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic
41RISK
open ↗VulnCheck XDB
initial-access
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open ↗GitHub PoC
Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RISK
open ↗VulnCheck XDB
infoleak
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open ↗GitHub PoC
Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open ↗GitHub PoC
Automatic python script using cve-2022-44268 to add a profile value with a filename from a input filelist in an input file.
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open ↗GitHub PoC
Checks projects for compromised packages, suspicious files, and import statements.
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RISK
open ↗GitHub PoC
Report written on CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability
93RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.