Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,151cataloged exploits
35,370CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,233GitHub PoC 14,119VulnCheck XDB 8,617Nuclei 4,257Metasploit 3,474✓ verified onlyrecentpopularrisk
77,020 exploits
GitHub PoC★ 2
Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISK
open ↗GitHub PoC★ 1
muhammad1596/CVE-2022-0847-dirty-pipe-checker
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC★ 27
Apache OFBIZ Path traversal leading to RCE POC[CVE-2024-32113 & CVE-2024-36104]
Apache OFBiz: Path traversal leading to RCE
100RISK
open ↗GitHub PoC★ 3
Sonatype Nexus Repository Manager 3 (LFI)
Nexus Repository 3 - Path Traversal
61RISK
open ↗Metasploit0
macOS PackageKit ZSH Environment Privilege Escalation
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to
36RISK
open ↗GitHub PoC
Exploit created by nu11secur1ty (https://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2022-37706)
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open ↗GitHub PoC★ 79
Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)
Registration Authentication Bypass Vulnerability
100RISK
open ↗GitHub PoC★ 1
CVE-2023-51518: Preauthenticated Java Deserialization via JMX in Apache James
Apache James server: Privilege escalation via JMX pre-authentication deserialisation
48RISK
open ↗GitHub PoC★ 3
CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.
Information disclosure
100RISK
open ↗VulnCheck XDB
local
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open ↗GitHub PoC★ 2
kevcooper/CVE-2024-1086-checker
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open ↗GitHub PoC★ 19
Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open ↗GitHub PoC★ 1
New exploit for Apache APISIX v2.12.1 - Remote code execution (RCE)
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RISK
open ↗GitHub PoC★ 3
CVE-2024-24919 Sniper - A powerful tool for scanning Check Point Security Gateway CVE-2024-24919 vulnerability. Supports single & bulk scanning, multithreading, and generates detailed CSV reports. Ideal for penetration testers and security researchers.
Information disclosure
100RISK
open ↗GitHub PoC★ 1
phpMyAdmin <4.9.0 - Cross-Site Request Forgery
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF
28RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.