Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
AllExploit-DB 22,786Referência 20,023GitHub PoC 13,334VulnCheck XDB 8,195Nuclei 4,217Metasploit 3,463✓ verified onlyrecentpopularrisk
13,334 exploits
GitHub PoC
mrrivaldo/CVE-2025-2294
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open ↗GitHub PoC
Unauthenticated SQL injection exploit for CVE-2019-9053 in CMS Made Simple <= 2.2.9. Extracts admin creds with time-based SQLi.
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗GitHub PoC
B1gN0Se/Tomcat-CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC
Next.js Auth Bypass Lab ‐ CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 1
Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 1
This repository contains a shell script based POC on Apache Tomcat CVE-2025-24813. It allow you to easily test the vulnerability on any version of Apache Tomcat
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 1
Sets up a local Tapo C200 using CVE-2021-4045
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open ↗GitHub PoC★ 9
IngressNightmare-PoC: (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) PoC ,One-click script 。 一键脚本
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISK
open ↗GitHub PoC
thunww/CVE-2024-50379
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open ↗GitHub PoC
cyberdesu/Elastix-2.2.0-CVE-2012-4869
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RISK
open ↗GitHub PoC★ 1
A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd and /etc/shadow. POC
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open ↗GitHub PoC
CVE-2009-1151, phpMyAdmin의 set.up
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISK
open ↗GitHub PoC
cve-2022-26134 atlassia Confluence Data Center2016 server OGNL %[...}
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open ↗GitHub PoC★ 1
cesarbtakeda/Windows-Explorer-CVE-2025-24071
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open ↗GitHub PoC
Sornphut/CVE-2023-7028-GitLab
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open ↗GitHub PoC★ 2
This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
Next.js CVE-2025-29927 demonstration
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
dustblessnotdust/CVE-2024-25180
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf
48RISK
open ↗GitHub PoC★ 1
Here is a simple but effective exploit for CVE-2025-29927.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 3
Create lab for CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 1
CVE-2025-30208 ViteVulnScanner
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗GitHub PoC★ 12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISK
open ↗GitHub PoC★ 1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
ingress-nginx admission controller RCE escalation
85RISK
open ↗GitHub PoC
This repository is for educational and research purposes.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 3
CVE-2025-29927: Next.js Middleware Exploit
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 91
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open ↗GitHub PoC★ 9
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.