Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
76,313 exploits
Exploit-DB
NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RISK
open ↗GitHub PoC★ 2
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 8
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 248
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISK
open ↗VulnCheck XDB
infoleak
WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability
56RISK
open ↗GitHub PoC★ 1
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
48RISK
open ↗GitHub PoC
A root exploit for CVE-2022-0847 (Dirty Pipe)
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC★ 2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
Azure Storage Resource Provider Spoofing Vulnerability
48RISK
open ↗Metasploit600
Appsmith RCE
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea
43RISK
open ↗GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RISK
open ↗VulnCheck XDB
initial-access
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open ↗GitHub PoC
CVE-2025-22912
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RISK
open ↗GitHub PoC★ 3
script to check cve "CVE-2025-29927" while waiting to add it to HExHTTP
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 1
PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios d'attaque, analyse des risques et serveur Express.js de test.
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC
The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
maronnjapan/claude-create-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
Critical vulnerability in next.js : Bypass middleware authentication
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
somatrasss/CVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open ↗GitHub PoC★ 2
PowerShell script to test if a web app is vulnerable to CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 5
PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 9
Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)
Authorization Bypass in Next.js Middleware
85RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.