Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,003GitHub PoC 13,307VulnCheck XDB 8,182Nuclei 4,217Metasploit 3,462✓ verified onlyrecentpopularrisk
13,307 exploits
GitHub PoC★ 2
r0otk3r/CVE-2025-47812
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open ↗GitHub PoC
QHxDr-dz/CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗GitHub PoC
Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open ↗GitHub PoC★ 3
This document describes a Denial of Service (DoS) vulnerability found in certain versions of MikroTik RouterOS. The vulnerability is due to insufficient handling of crafted SMB requests. A remote attacker could exploit this issue by sending a specially crafted request to the target server.
Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (devic
41RISK
open ↗GitHub PoC
jkobierczynski/cve-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open ↗GitHub PoC
Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RISK
open ↗GitHub PoC
Checks projects for compromised packages, suspicious files, and import statements.
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst
71RISK
open ↗GitHub PoC
This is my implementation of shellshock exploit
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC
Report written on CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability
93RISK
open ↗GitHub PoC★ 10
Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open ↗GitHub PoC
G01d3nW01f/cve-2023-27372
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open ↗GitHub PoC
Just a quick script I cooked up to exploit CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Honeypot for CVE-2025-53770 aka ToolShell
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
Udyz/CVE-2025-53770-Exploit
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
elprogramadorgt/CVE-2025-48384
Git allows arbitrary code execution through broken config quoting
71RISK
open ↗GitHub PoC★ 4
This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious `CIF` file to the hosted `CIF Analyzer` website on the target running on the Chemistry machine from Hack the Box.
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open ↗GitHub PoC★ 2
Do you really think SharePoint is safe?
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Detection rules for CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
rob0tstxt/POC-CVE-2025-5777
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open ↗GitHub PoC
bharath-cyber-root/sharepoint-toolshell-cve-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 2
Fineken/Jenkins-CVE-2024-23897-Lab
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗GitHub PoC★ 7
DevBuiHieu/CVE-2025-6558-Proof-Of-Concept
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RISK
open ↗GitHub PoC
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
PoC exploit and vulnerable server demo for CVE-2025-1302 in jsonpath-plus.
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RISK
open ↗GitHub PoC★ 1
Nuclei template to detect CVE-2024-6387. All latest patched versions are excluded.
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
shan0ar/cve-2025-32756
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open ↗GitHub PoC
A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over testing parameters, multiple attack patterns, and advanced monitoring capabilities.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗GitHub PoC
Proof-of-concept LFI Scanner: Automated detection of /etc/passwd exposures via directory traversal and regex matching.
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RISK
open ↗GitHub PoC★ 1
WordPress联系表单插件 - 未授权任意文件上传漏洞
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RISK
open ↗GitHub PoC★ 8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.