Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,934GitHub PoC 13,235VulnCheck XDB 8,150Nuclei 4,193Metasploit 3,462✓ verified onlyrecentpopularrisk
13,235 exploits
GitHub PoC★ 1
A new way to exploit CVE-2025-58360 bypass WAF
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open ↗GitHub PoC
Rishi-kaul/CVE-2025-14847-MongoBleed
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 2
nkuty/CVE-2025-54322-exploit
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
53RISK
open ↗GitHub PoC
Goultarde/CVE-2025-55182-React2Shell-Lab
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade vers Root (SUID). Ce dépôt contient le rapport technique détaillé, les preuves d'exploitation (PoC) et les mesures de remédiation pour sécuriser l'infrastructure.
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open ↗GitHub PoC
🎯 Automated vulnerability scanner for React2Shell RCE - Google dorking + safe detection for CVE-2025-55182/CVE-2025-66478 (CVSS 10.0)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It demonstrates how the exploit works, including the payload and impact.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules
Argument Injection in PHP-CGI
100RISK
open ↗GitHub PoC
YanC1e/CVE-2025-8191
macrozheng mall Swagger UI index.html cross site scripting
33RISK
open ↗GitHub PoC
Remake of CVE-2025-14847 MongoDB vulnerability demonstration
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 1
This repository contains a safe Proof of Concept (PoC) to detect vulnerable SmarterMail versions affected by CVE‑2025‑52691. The script performs version detection only and does not exploit the vulnerability.
Upload Arbitrary Files
100RISK
open ↗GitHub PoC★ 3
An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation, persistence, exfiltration, and interactive mode. For educational and authorized testing only. Credits to the original PoC by yt2w/CVE-2025-52691.
Upload Arbitrary Files
100RISK
open ↗GitHub PoC
Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RISK
open ↗GitHub PoC★ 2
Academic proof-of-concept demonstrating CVE-2025-68645 for authorized security research.
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open ↗GitHub PoC★ 1
CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 1
This repo contains my python script version of CVE-2025-14847 (MongoBleed)
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗GitHub PoC
Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
Rishi-kaul/n8n-CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC★ 4
Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 13
Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
cv-sai-kamesh/n8n-CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC★ 1
CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 1
aexdyhaxor/CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC
Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847.
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.