Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,044GitHub PoC 15,521VulnCheck XDB 9,080Nuclei 4,432Metasploit 3,505✓ verified onlyrecentpopularrisk
81,064 exploits
GitHub PoC★ 1
obscura-cert/CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open ↗GitHub PoC★ 1
POC for PDF JS' CVE-2024-4367 vuln
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC
aninfosec/CVE-2024-43425-Poc
Moodle: remote code execution via calculated question types
78RISK
open ↗VulnCheck XDB
initial-access
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open ↗GitHub PoC★ 2
POC for PDF JS' CVE-2024-4367 vuln
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗VulnCheck XDB
remote-with-credentials
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open ↗GitHub PoC★ 3
Proof-of-concept and analysis for CVE-2025-32711
M365 Copilot Information Disclosure Vulnerability
48RISK
open ↗GitHub PoC★ 10
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗GitHub PoC
Escala de privilegios con CVE-2010-5195
Untrusted search path vulnerability in Roxio MyDVD 9 allows local users to gain privileges via a Trojan horse HomeUtils9
23RISK
open ↗GitHub PoC★ 21
Unauthenticated Python PoC for CVE-2025-20281 RCE against ISE ERS API
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
Security analysis project: Real-world CVE breakdown
Xz: malicious code in distributed source
70RISK
open ↗VulnCheck XDB
initial-access
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open ↗Metasploit300
Marvell QConvergeConsole Path Traversal (CVE-2025-6793)
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
48RISK
open ↗Metasploit600
PandoraFMS Netflow Authenticated Remote Code Execution
Command Injection in Netflow path
48RISK
open ↗GitHub PoC
The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to extract potentially sensitive information from server memory over the TLS protocol.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open ↗GitHub PoC★ 17
speinador/CVE-2025-6218_WinRAR
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open ↗VulnCheck XDB
client-side
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open ↗Exploit-DB
Sitecore 10.4 - Remote Code Execution (RCE)
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RISK
open ↗GitHub PoC★ 4
Remote Code execution in CentOS web panel
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open ↗Exploit-DB
PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISK
open ↗GitHub PoC★ 7
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISK
open ↗GitHub PoC★ 5
Script para determinar si Citrix es vulnerable al CVE-2025-6543
Memory overflow vulnerability leading to unintended control flow and Denial of Service
83RISK
open ↗Exploit-DB
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISK
open ↗Exploit-DB
Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗Exploit-DB
McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
Improper Verification of Cryptographic Signature by McAfee Agent
33RISK
open ↗Exploit-DB
Microsoft Excel 2024 Use after free - Remote Code Execution (RCE)
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.