Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,497GitHub PoC 13,627VulnCheck XDB 8,198Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
75,444 exploits
VulnCheck XDB
remote-with-credentials
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗VulnCheck XDB
client-side
Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting
56RISK
open ↗GitHub PoC
Ushbu videoda Kali Linux orqali Metasploitable 2 serveriga PHP CGI Argument Injection (CVE-2012-1823) ekspluatatsiyasi Metasploit yordamida amalga oshiriladi
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open ↗GitHub PoC
🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC★ 2
A evolved version of assetnote CVE-2025-55182 scanner
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
验证 Gogs 版本 0.13.2 是否存在 **CVE-2025-8110 (符号链接文件覆盖)** 漏洞。
File overwrite in file update API in Gogs
100RISK
open ↗GitHub PoC
基于Pocsuite3 框架编写的漏洞验证与利用脚本,用于检测 n8n工作流自动化工具中的认证后远程代码执行漏洞(RCE)
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
Analysis of CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
intelligent-ears/CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
Technical audit of Kioptrix Level 1. Focus: Samba 2.2.1a exploitation (CVE-2003-0201), manual enumeration, and internal infrastructure hardening.
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗GitHub PoC
GUI Shodan-powered scanner to identify n8n instances exposed to CVE-2025-68613 (version range 0.211.0–1.122.0)
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
AnGrY-Althaf/CVE-2024-40110
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability
48RISK
open ↗GitHub PoC
zakaria-laouani/cve-2023-0669-simulation
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISK
open ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
initial-access
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC★ 1
Instructions for rapid deployment of Tomcat v9.0.90 with java 25.0.1 2025-10-21 LTS on Windows Server 2019 Standard for lazy researchers.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC
Ushbu videoda Metasploitable 2 tizimidagi distccd servisidagi zaiflikdan foydalanib, Kali Linux orqali remote shell olish ko‘rsatib beriladi.
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC★ 1
js2py sandbox escape to reverse shell
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RISK
open ↗GitHub PoC★ 2
CVE-2025-62215: Windows Kernel Race Condition + Double-Free EoP
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC★ 1
Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup
48RISK
open ↗GitHub PoC
CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation modules, stealth capabilities, and comprehensive documentation. For authorized testing only.
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC
POC for CVE-2025-68613
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**.
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
machevalia/CVE-2025-14733
WatchGuard Firebox iked Out of Bounds Write Vulnerability
83RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.