Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,581GitHub PoC 13,708VulnCheck XDB 8,225Nuclei 4,228Metasploit 3,467✓ verified onlyrecentpopularrisk
75,652 exploits
GitHub PoC
Kento-Sec/CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗VulnCheck XDB
initial-access
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗GitHub PoC
CVE-2025-53770 - SharePoint
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
Exploration of the Follina (CVE-2022-30190) Microsoft Office vulnerability, including a detailed analysis, proof-of-concept exploitation in a controlled lab, and mitigation strategies. For educational and research purposes only.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
n0m-d/CVE-2018-0114-Go
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open ↗GitHub PoC
PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗GitHub PoC
benguelmas/cve-2017-0143
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open ↗GitHub PoC★ 55
POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open ↗GitHub PoC★ 3
zenzue/CVE-2025-50154
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open ↗GitHub PoC
CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC
oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISK
open ↗VulnCheck XDB
initial-access
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗GitHub PoC★ 7
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open ↗GitHub PoC
Proof of concept for the vulnerability CVE-2025-50428: Authenticated OS Command Injection in RaspAP
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script.
48RISK
open ↗GitHub PoC★ 1
PoC of CVE-2025-47533 Clobber RCE
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open ↗GitHub PoC★ 71
CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)
Path traversal vulnerability in WinRAR
93RISK
open ↗VulnCheck XDB
client-side
Git allows arbitrary code execution through broken config quoting
71RISK
open ↗GitHub PoC
Dissecting CVEin Chrome
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISK
open ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗GitHub PoC★ 1
Esse script explora a vulnerabilidade CVE-2025-20124 — uma falha de Java Deserialization no Cisco ISE (Identity Services Engine) que permite Remote Code Execution (RCE).
Cisco Identity Services Engine Java Deserialization Vulnerability
53RISK
open ↗GitHub PoC★ 1
00xCanelo/CVE-2024-47533-PoC
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open ↗GitHub PoC★ 1
PoC of CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗GitHub PoC
Berisi 2 program C dari exploitDB untuk melakukan privillage eskalation untuk ubuntu 16.04
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open ↗GitHub PoC
Program python untuk melakukan RCE pada drupal versi 7.56
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open ↗GitHub PoC★ 8
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open ↗GitHub PoC★ 46
WinRAR 0day CVE-2025-8088 PoC RAR Archive
Path traversal vulnerability in WinRAR
93RISK
open ↗VulnCheck XDB
infoleak
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga
61RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.