Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,692GitHub PoC 13,812VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
76,107 exploits
VulnCheck XDB
client-side
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
71RISK
open ↗GitHub PoC★ 2
CVE-2025-24813-POC JSP Web Shell Uploader
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RISK
open ↗GitHub PoC★ 1
cybermads/CVE-2011-2523
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open ↗GitHub PoC
VVeakee/CVE-2024-4367
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC
d0x-awrqxavc/-CVE-2024-10924
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open ↗GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISK
open ↗GitHub PoC
Koray123-debug/CVE-2024-34102
XXE can expose crypt key and other secrets granting full admin access
100RISK
open ↗Exploit-DB
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISK
open ↗Exploit-DB
Watcharr 1.43.0 - Remote Code Execution (RCE)
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
41RISK
open ↗GitHub PoC★ 33
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open ↗Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
DataEase has database configuration information exposure vulnerability
53RISK
open ↗VulnCheck XDB
initial-access
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open ↗GitHub PoC★ 3
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISK
open ↗VulnCheck XDB
local
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open ↗Exploit-DB
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
IBM Security Verify Access HTTP open redirect
33RISK
open ↗GitHub PoC★ 4
simple exp for CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 1
Apache Tomcat is vulnerable to a Path Equivalence / Path Traversal issue due to improper handling of ../ sequences in paths.
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗GitHub PoC★ 2
Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗VulnCheck XDB
initial-access
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open ↗Exploit-DB
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.