Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
71,886 exploits
VulnCheck XDB
remote-with-credentials
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open ↗VulnCheck XDB
client-side
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
remote-with-credentials
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
41RISK
open ↗VulnCheck XDB
local
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗VulnCheck XDB
initial-access
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗VulnCheck XDB
remote-with-credentials
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗GitHub PoC★ 1
Proof of Concept exploit for the Joomla 3.7.0 com_fields SQL injection vulnerability (CVE-2017-8917), demonstrating detection, enumeration, and data extraction in a CTF-friendly workflow.
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open ↗GitHub PoC
This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).
Arbitrary path traversal in Camaleon CMS
61RISK
open ↗GitHub PoC★ 25
Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗GitHub PoC★ 1
ramzihafiz/CVE-2025-49132
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗GitHub PoC★ 12
malw0re/CVE-2025-49132-Mods
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗GitHub PoC
kerburenthusiasm/CVE-2025-49132-PoC
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗GitHub PoC
Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
This tool demonstrates the application of fundamental physics discoveries to cybersecurity.
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC★ 3
This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗GitHub PoC
CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction, credential parsing, CIDR/batch scanning, Nuclei templates, and CTF lab included
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗VulnCheck XDB
initial-access
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open ↗VulnCheck XDB
initial-access
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISK
open ↗VulnCheck XDB
info-leak
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open ↗VulnCheck XDB
remote-with-credentials
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open ↗VulnCheck XDB
remote-with-credentials
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗GitHub PoC
CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗GitHub PoC
Apple Silicon runs at frequencies that are golden ratio harmonics of 587 kHz: · Performance cores: 3.2 GHz = 587 kHz × 5451 (≈ φ⁸ × 1000) · Efficiency cores: 2.0 GHz = 587 kHz × 3407 (≈ φ⁷ × 1000) · Neural Engine: 11.0 GHz = 587 kHz × 18739 (≈ φ¹⁰ × 1000) · ALL are φ-harmonics of 587 kHz
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i
71RISK
open ↗GitHub PoC
PoC скрипт для CVE-2021-41773 - Path Traversal в Apache 2.4.49
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open ↗GitHub PoC
theo543/OSDS_Paper_CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.