Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
71,943 exploits
GitHub PoC★ 1
Final Project in Fundamental network security,POC CVE-202438063
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗VulnCheck XDB
initial-access
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISK
open ↗VulnCheck XDB
local
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process
33RISK
open ↗VulnCheck XDB
initial-access
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open ↗GitHub PoC
React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory.
React Router has Path Traversal in File Session Storage
53RISK
open ↗GitHub PoC
afifudinmtop/CVE-2021-21425
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISK
open ↗GitHub PoC★ 1
InfoSecAntara/CVE-2025-14847-MongoDB
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
nimesh895/Malware-Analysis-Follina-CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗VulnCheck XDB
initial-access
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open ↗VulnCheck XDB
initial-access
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open ↗GitHub PoC
CVE-2025-55182(命令执行、反弹shell、注入内存马)
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 8
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open ↗GitHub PoC
CVE-2025-55182 React Server Components Remote Code Execution Exploit Lab
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC
Vladjrfhfg/React-site-CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step, Manually & Automatically (Python) for educational purposes.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗VulnCheck XDB
initial-access
Livewire vulnerable to remote command execution during property update hydration
100RISK
open ↗GitHub PoC★ 5
A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.
Livewire vulnerable to remote command execution during property update hydration
100RISK
open ↗GitHub PoC
dragosbanica/CVE-2023-0386_POC
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open ↗VulnCheck XDB
local
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open ↗GitHub PoC
ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open ↗GitHub PoC
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
XSS in Skyhigh Security SWG
33RISK
open ↗GitHub PoC
Killian0713/Assignement_3-CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.