Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,459Referência 22,721GitHub PoC 14,946VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
3,489 exploits
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
N-central Multiple XXE Injection Vulnerabilities
68RISK
open ↗Metasploit600
Fortinet FortiWeb unauthenticated RCE
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open ↗Metasploit300
Fortinet FortiWeb create new local admin
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open ↗Metasploit600
Fortinet FortiWeb unauthenticated RCE
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISK
open ↗Metasploit600
FreePBX filestore authenticated command injection
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RISK
open ↗Metasploit600
Monsta FTP downloadFile Remote Code Execution
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open ↗Metasploit600
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISK
open ↗Metasploit600
WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
43RISK
open ↗Metasploit600
Taiga tribe_gig authenticated unserialize remote code execution
Taiga Authenticated Remote Code Execution
43RISK
open ↗Metasploit500
Windows Server Update Service Deserialization Remote Code Execution
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open ↗Metasploit600
SmarterTools SmarterMail GUID File Upload Vulnerability
Upload Arbitrary Files
100RISK
open ↗Metasploit600
Oracle E-Business Suite CVE-2025-61882 RCE
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open ↗Metasploit600
Centreon authenticated command injection leading to RCE via broker engine "reload" parameter
RCE via the poller reload feature available only to user with high privilege
41RISK
open ↗Metasploit600
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open ↗Metasploit600
FreePBX ajax.php unauthenticated SQLi to RCE
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Argument Injection Vulnerability in CommServe
33RISK
open ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Path Traversal Vulnerability
41RISK
open ↗Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
Unauthorized API Access Risk
28RISK
open ↗Metasploit600
Flowise Custom MCP Remote Code Execution
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
65RISK
open ↗Metasploit600
Grav CMS Admin Direct Install Authenticated Plugin Upload RCE
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RISK
open ↗Metasploit400
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (time param)
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISK
open ↗Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Template Import
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
63RISK
open ↗Metasploit600
WordPress StoryChief Plugin Unauthenticated RCE
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open ↗Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISK
open ↗Metasploit600
PivotX Remote Code Execution
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RISK
open ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Server Spoofing Vulnerability
50RISK
open ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Remote Code Execution Vulnerability
88RISK
open ↗Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.