Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,662GitHub PoC 13,743VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
76,008 exploits
VulnCheck XDB
initial-access
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RISK
open ↗GitHub PoC
abrewer251/CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open ↗VulnCheck XDB
infoleak
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISK
open ↗GitHub PoC★ 8
NULLTRACE0X/CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗VulnCheck XDB
initial-access
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗VulnCheck XDB
infoleak
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open ↗GitHub PoC
Vite WASM Import Path Traversal 🛡️
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISK
open ↗GitHub PoC★ 1
Exploitation report of the Samba Trans2Open vulnerability (CVE-2003-0201), including tools used, exploitation steps, and protection techniques to secure systems.
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open ↗GitHub PoC★ 2
exploiting CVE-2025-27007, a critical unauthenticated privilege escalation vulnerability in the OttoKit (formerly SureTriggers) WordPress plugin
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RISK
open ↗GitHub PoC★ 1
1Altruist/CVE-2025-46271-Reverse-Shell-PoC
Planet Technology Network Products OS Command Injection
48RISK
open ↗GitHub PoC★ 1
Next.js Auth Bypass PoC Edge Runtime Env Leak via Middleware Bug
Authorization Bypass in Next.js Middleware
85RISK
open ↗Exploit-DB
Grokability Snipe-IT 8.0.4 - Insecure Direct Object Reference (IDOR)
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
33RISK
open ↗Exploit-DB
ERPNext 14.82.1 - Account Takeover via Cross-Site Request Forgery (CSRF)
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allow
41RISK
open ↗VulnCheck XDB
initial-access
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗GitHub PoC★ 5
Research Purposes only
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open ↗VulnCheck XDB
infoleak
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open ↗GitHub PoC
Hirainsingadia/CVE-2002-2154
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (do
23RISK
open ↗GitHub PoC
abrewer251/CVE-2025-1974_IngressNightmare_PoC
ingress-nginx admission controller RCE escalation
85RISK
open ↗VulnCheck XDB
initial-access
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗GitHub PoC★ 1
PoC for CVE-2025-2011 - SQLi in Depicter plugin <= 3.6.1
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open ↗VulnCheck XDB
initial-access
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗GitHub PoC★ 1
Commvault Remote Code Execution (CVE-2025-34028) NSE
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗GitHub PoC★ 2
Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or multiple targets, executes commands, and reports vulnerable hosts.
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open ↗GitHub PoC
NGINX DNS Overflow Vulnerability Check - CVE-2021-23017 PoC
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
initial-access
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open ↗VulnCheck XDB
initial-access
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗GitHub PoC★ 1
Scanner and exploit for CVE-2025-3248
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open ↗GitHub PoC★ 1
CVE-2025-4524 - Unauthenticated madara-core Wordpress theme LFI
Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.