Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
72,018 exploits
VulnCheck XDB
remote-with-credentials
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC★ 3
Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive suitable for offline investigation on a forensic workstation.
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
n8n CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
bodoinon/CVE-2024-10924
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open ↗GitHub PoC
CVE-2025-20393
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open ↗GitHub PoC★ 2
Proof of Concept for CVE-2025-24893 demonstrating unauthenticated remote command execution in XWiki through unsafe server-side template evaluation.
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗GitHub PoC
webmin/usermin 2.100
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RISK
open ↗GitHub PoC
KingHacker353/R2C-CVE-2025-55182-66478
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 3
A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
60RISK
open ↗VulnCheck XDB
initial-access
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open ↗VulnCheck XDB
info-leak
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
saereya/CVE-2025-14847---MongoBleed
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 36
MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC
This is a standalone Python implementation for CVE-2024-46506. I created this script because I could only find the Metasploit module and needed a lightweight, portable version that doesn't require the full Metasploit Framework.
NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun
75RISK
open ↗GitHub PoC★ 31
a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnerable MongoDB instances.
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 1
flame-11/CVE-2018-9206-jquery-file-upload
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open ↗GitHub PoC
KingHacker353/CVE-2025-14847_Expolit
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗GitHub PoC★ 3
PoC para determinar si Fortinet es vulnerable a CVE-2025-59718 / CVE-2025-59719
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0
90RISK
open ↗GitHub PoC
CVE-2023-5360 PoC: Unauthenticated arbitrary file upload leading to RCE in Royal Elementor Addons (≤ 1.3.78), written in pure Python.
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open ↗GitHub PoC★ 2
golang test tool for mongobleed (cve-2025-14847)
Zlib compressed protocol header length confusion may allow memory read
100RISK
open ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 1
PoC For CVE-2024-30167 (Atlona OME Authenticated Command Injection)
/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary comm
33RISK
open ↗VulnCheck XDB
initial-access
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.