Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 19,978GitHub PoC 13,282VulnCheck XDB 8,176Nuclei 4,202Metasploit 3,462✓ verified onlyrecentpopularrisk
13,282 exploits
GitHub PoC
KylVGoi/cve-2019-1663
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open ↗GitHub PoC
CVE-2018-10933 - LibSSH - Authentication Bypass
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open ↗GitHub PoC★ 1
m2hcz/CVE-2025-6440-Poc-Exploit
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open ↗GitHub PoC
xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
Path traversal vulnerability in WinRAR
93RISK
open ↗GitHub PoC
sec-dojo-com/CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RISK
open ↗GitHub PoC
Exploit - CVE-2023-26360
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open ↗GitHub PoC
Modified the CVE-2024-25600
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗GitHub PoC
CVE-2010-2075
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open ↗GitHub PoC★ 4
Secure expression evaluator - Drop-in replacement for expr-eval without CVE-2025-12735 vulnerability
CVE-2025-12735
48RISK
open ↗GitHub PoC
TeamCity 2023.05.3 - CVE-2023-42793 - Create username administrator.
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open ↗GitHub PoC★ 1
Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests past proxies and load balancers in vulnerable ASP.NET Core/Kestrel servers.
ASP.NET Security Feature Bypass Vulnerability
60RISK
open ↗GitHub PoC★ 1
CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗GitHub PoC★ 6
XXE through a specific endpoint /geoserver/wms operation GetMap - Geoserver
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open ↗GitHub PoC
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open ↗GitHub PoC
CVE-2021-43798 is a high-severity path traversal vulnerability (CVSS 3.1 score: 7.5) affecting Grafana versions 8.0.0-beta1 through 8.3.0. It allows unauthenticated attackers to read arbitrary files from the server by exploiting improper sanitization in the /public/plugins/:pluginId endpoint
Grafana path traversal
100RISK
open ↗GitHub PoC★ 1
CVE-2017-7921 is a critical vulnerability (CVSS score: 9.8) affecting multiple Hikvision IP camera and DVR models, first disclosed in 2017. It stems from an improper authentication flaw that allows unauthenticated remote attackers to bypass login mechanisms and gain unauthorized access to sensitive system information
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open ↗GitHub PoC
CVE-2025-58360
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open ↗GitHub PoC
Chroot Privilege Escalation
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC
OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0
Samba: command injection in wins server hook script
60RISK
open ↗GitHub PoC★ 2
ExtremeUday/CVE-2025-2945-pgAdmin4-Authenticated-RCE-PoC-
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISK
open ↗GitHub PoC
CVE-2025-6389
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RISK
open ↗GitHub PoC
Path Traversal Apache HTTP Server 2.4.49/2.4.50
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
yunus-a1i/veeam-cve-2023-27532-mock
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database
93RISK
open ↗GitHub PoC★ 3
PoC RCE exploit for Nostromo nhttpd ≤ 1.9.6
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open ↗GitHub PoC★ 2
Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open ↗GitHub PoC
CVE-2025-61757
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISK
open ↗GitHub PoC★ 2
Reproducing CVE-2024-29943 for Windows, based on https://github.com/bjrjk/CVE-2024-29943
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec
53RISK
open ↗GitHub PoC★ 31
aklnjakln/CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open ↗GitHub PoC
Proof-of-Concept (PoC) for CVE-2025-62168 👾
Squid vulnerable to information disclosure via authentication credential leakage in error handling
75RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.