Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
13,235 exploits
GitHub PoC
Vladjrfhfg/React-site-CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 8
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open ↗GitHub PoC
ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
This script audits ServiceNow AI Agents for vulnerabilities like CVE-2025-12420, governance gaps, and compliance risks. Powered by CYBERDUDEBIVASH – your global ecosystem for cybersecurity, AI apps, services, and consulting.
Unauthenticated Privilege Escalation in ServiceNow AI Platform
60RISK
open ↗GitHub PoC
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open ↗GitHub PoC
Killian0713/Assignement_3-CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗GitHub PoC
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
XSS in Skyhigh Security SWG
33RISK
open ↗GitHub PoC
This repository provides a high-fidelity technical deconstruction and production-ready exploitation suite for CVE-2019-5736. It demonstrates how a root user inside a container can achieve a Host Root Shell by overwriting the host runc binary using an OverlayFS mount and ld.so.preload manipulation.
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open ↗GitHub PoC★ 2
Teodor1231241/DEMO-Proof-of-Concept-Temporal-Memory-Inconsistency-in-cldflt.sys-CVE-2025-62221
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.
WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution
48RISK
open ↗GitHub PoC
Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive suite—featuring multi-vector rotations, HTTP/2 Rapid Reset (CVE-2023-44487) exploitation, and mTLS 1.3-encrypted C2 orchestration—with a high-integrity 7-Tier Blue Elite Teaming defense-in-depth architecture.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗GitHub PoC
rdana55/CVE-2021-29447-PoC
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open ↗GitHub PoC★ 2
Overview of a application that I reversed using the CVE-2015-2291 exploit from the Intel Ethernet Diagnostics Driver (iQVW32.sys) for memory manipulation used in hwid spoofing.
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISK
open ↗GitHub PoC
Exploitation report for ProFTPD 1.3.5 mod_copy (CVE-2015-3306) lab.
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open ↗GitHub PoC
Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗GitHub PoC
Comprehensive 100% Unrestricted Technical Analysis of JAGUAR_TOOTH Malware (APT28). High-precision reconstruction of Cisco IOS SNMP exploitation, ROP chaining, and memory-resident espionage tactics by SASTRA_ADI_WIGUNA.
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the aff
76RISK
open ↗GitHub PoC
This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known post-exploitation IOCs.
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open ↗GitHub PoC
faisha1311/React2Shell-CVE-2025-55182-TryHackMe
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
Kai-One001/React-Router-CVE-2025-61686-
React Router has Path Traversal in File Session Storage
53RISK
open ↗GitHub PoC★ 1
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-specific attacks (CVE-2022-21449, CVE-2018-0114).
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open ↗GitHub PoC
Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a Metasploitable 2 machine with a reverse shell to access the root folder. Once this folder has been accessed, it should reveal the /etc/shadow folder which would give proof of compromise.
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open ↗GitHub PoC
dkq-k/CVE-2023-22515
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗GitHub PoC★ 2
LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
A simple Python proof-of-concept tool to check for Apache path traversal vulnerability (CVE-2021-41773). Detects vulnerable server versions and verifies exploitation by probing sensitive files. Built for learning CVE analysis, not mass exploitation.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC★ 1
Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521)
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
41RISK
open ↗GitHub PoC
dkq-k/cve-2023-22515-1
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗GitHub PoC
End-to-end remediation of CVE-2013-3900 using PowerShell and Tenable. Demonstrates vulnerability identification, registry hardening, and automated verification in an Azure environment
WinVerifyTrust Signature Validation Vulnerability
75RISK
open ↗GitHub PoC
CVE-2025-61686复现的dockerfile与poc
React Router has Path Traversal in File Session Storage
53RISK
open ↗GitHub PoC
🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.