Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,482Referência 24,044GitHub PoC 15,521VulnCheck XDB 9,080Nuclei 4,432Metasploit 3,505✓ verified onlyrecentpopularrisk
81,064 exploits
GitHub PoC★ 7
Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗GitHub PoC★ 3
Mass-CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗GitHub PoC★ 4
Pterodactyl翼龙面板CVE-2025-49132批量检测☝️🤓
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗GitHub PoC
cuerv0x/CVE-2015-6967
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗VulnCheck XDB
infoleak
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗GitHub PoC★ 1
CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open ↗GitHub PoC★ 2
Check a list of Pterodactyl panels for vulnerabilities from a file.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗VulnCheck XDB
initial-access
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISK
open ↗VulnCheck XDB
initial-access
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISK
open ↗GitHub PoC
CVE 2018-9035: CSV Injection in Wordpress with plugin Contact Form 7 to Database Extension 2.10.3
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RISK
open ↗GitHub PoC★ 1
sendINUX/CVE-2021-22600__DirtyPagetable
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISK
open ↗VulnCheck XDB
local
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISK
open ↗GitHub PoC★ 17
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗VulnCheck XDB
infoleak
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open ↗GitHub PoC★ 1
Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open ↗VulnCheck XDB
remote-with-credentials
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open ↗VulnCheck XDB
initial-access
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RISK
open ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗GitHub PoC
gmh5225/CVE-2025-1562
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISK
open ↗GitHub PoC
tomcat CVE-2025-24813 反序列化RCE环境
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 4
mbanyamer/PX4-Military-UAV-Autopilot-1.12.3-Stack-Buffer-Overflow-Exploit-CVE-2025-5640-
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.