Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
71,886 exploits
GitHub PoC★ 1
Unauthenticated remote code execution vulnerability in Wing FTP Server <= 7.4.3.
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗GitHub PoC★ 1
这是基于cve-2016-4437简单的漏洞复现代码
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open ↗GitHub PoC
CVE-2014-6271 Exploit | by infrar3d
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC★ 4
CVE-2025-71243 - SPIP Saisies Plugin RCE (Unauthenticated PHP Code Injection)
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISK
open ↗VulnCheck XDB
local
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC
A deep-dive security analysis into the 2020 Virgin Mobile KSA data breach. This study dissects the exploitation of CVE-2020-0688, evaluates the impact of delayed patch management, and proposes a robust multi-layered defense architecture to prevent sophisticated exfiltration tactics.
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open ↗GitHub PoC
ross-ns/WSUS-CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open ↗Metasploit500
GrandStream GXP1600 Unauthenticated Remote Code Execution
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
75RISK
open ↗VulnCheck XDB
remote-with-credentials
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗VulnCheck XDB
info-leak
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RISK
open ↗GitHub PoC
Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow
Arbitrary writes via tarfile realpath overflow
48RISK
open ↗GitHub PoC★ 1
orgito1015/CVE-2025-55182-Researching-process
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗Metasploit600
MajorDoMo Remote Command Injection via cycle_execs Race Condition
MajorDoMo Command Injection in rc/index.php via Race Condition
43RISK
open ↗Metasploit600
MajorDoMo Console Eval Unauthenticated RCE
MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
63RISK
open ↗Metasploit600
MajorDoMo Supply Chain RCE via Update Poisoning
MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning
43RISK
open ↗GitHub PoC
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication, allowing arbitrary command execution as the web server user.
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗GitHub PoC
havbay/CVE-2025-47812-PoC
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗GitHub PoC★ 1
Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user.
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open ↗VulnCheck XDB
initial-access
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open ↗VulnCheck XDB
client-side
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗VulnCheck XDB
initial-access
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open ↗VulnCheck XDB
remote-with-credentials
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗VulnCheck XDB
initial-access
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗VulnCheck XDB
remote-with-credentials
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 2
CVE-2025-47812 POC
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗GitHub PoC
New CVE-2019-7609 which works with python 13
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open ↗GitHub PoC
andres101c/Shellshock-CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
initial-access
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open ↗GitHub PoC
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.