Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,554GitHub PoC 13,689VulnCheck XDB 8,216Nuclei 4,223Metasploit 3,464✓ verified onlyrecentpopularrisk
75,526 exploits
VulnCheck XDB
infoleak
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open ↗VulnCheck XDB
initial-access
Apache Camel: Camel Message Header Injection through request parameters
55RISK
open ↗GitHub PoC
Writeup for Tenda AC15 router firmware rehosting and remote command execution (CVE-2020-10987) exploit replication.
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary s
100RISK
open ↗GitHub PoC
srakkk/cve-2024-32002-demo
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC
srakkk/cve-2024-32002-hook
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open ↗GitHub PoC
Exploit for CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open ↗GitHub PoC
Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC
root Privileges
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗VulnCheck XDB
infoleak
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow re
100RISK
open ↗GitHub PoC
Redux Python3 Version of CVE-2010-2861
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow re
100RISK
open ↗VulnCheck XDB
client-side
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISK
open ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC
moeinmiadi/CVE-2015-1635_PoC
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open ↗VulnCheck XDB
denial-of-service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISK
open ↗VulnCheck XDB
initial-access
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open ↗VulnCheck XDB
remote-with-credentials
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISK
open ↗GitHub PoC★ 3
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 extension and universal compatible for Magento 2.3 & 2.4. If you cannot upgrade Magento or cannot apply the official hotfix, try this one.
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open ↗GitHub PoC
CaelumIsMe/CVE-2019-9053-POC
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗GitHub PoC★ 1
📋 ملخص مشروع MikroTik RouterOS 6.49.18 Exploit Kit 🎯 نظرة عامة تم إنشاء مشروع احترافي وشامل لاختراق أجهزة MikroTik RouterOS 6.49.18 يتضمن جميع المكونات المطلوبة مع واجهة عربية كاملة وتوثيق مفصل. ✅ المكونات المكتملة 1️⃣ سكربتات الاختراق (7 سكربتات ✅ المميزات الرئيسية 1🎯 دعم CVE-2023-30799 اقراء دليل ملخص شامل للاداة PROJECT_SUMMARY.md
MikroTik RouterOS Administrator Privilege Escalation
48RISK
open ↗GitHub PoC
Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking malicious request bodies.
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗VulnCheck XDB
initial-access
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISK
open ↗GitHub PoC
We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered msdt.exe execution, suggesting possible remote code execution on the host JonasPRD. Our task is to investigate the alert, confirm exploitation, assess impact, and recommend remediation.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics, Web Exploitation (SQLi, XSS), Cryptography, and Kernel Exploitation (OverlayFS/CVE-2015-1328) to achieve full root compromise.
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.