Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,692GitHub PoC 13,812VulnCheck XDB 8,460Nuclei 4,233Metasploit 3,467✓ verified onlyrecentpopularrisk
76,107 exploits
VulnCheck XDB
infoleak
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISK
open ↗VulnCheck XDB
initial-access
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗VulnCheck XDB
infoleak
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISK
open ↗Exploit-DB
Vite 6.2.2 - Arbitrary File Read
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗Exploit-DB
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
Hard coded default credential contained in install package
41RISK
open ↗Exploit-DB
AppSmith 1.47 - Remote Code Execution (RCE)
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
38RISK
open ↗Exploit-DB
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
Microsoft Office Spoofing Vulnerability
38RISK
open ↗GitHub PoC★ 7
CVE-2025-30208 - Vite Arbitrary File Read PoC
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗GitHub PoC★ 1
h4ckxel/CVE-2025-2005
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISK
open ↗GitHub PoC
Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)
Authorization Bypass in Next.js Middleware
85RISK
open ↗Exploit-DB
Webmin Usermin 2.100 - Username Enumeration
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RISK
open ↗Metasploit500
Ivanti Connect Secure Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISK
open ↗Metasploit300
Gladinet CentreStack/Triofox Path Traversal
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RISK
open ↗Exploit-DB
SAP NetWeaver - 7.53 - HTTP Request Smuggling
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open ↗GitHub PoC
User Registration & Membership <= 4.1.2 - Authentication Bypass
User Registration & Membership < 4.1.3 - Authentication Bypass
41RISK
open ↗Exploit-DB
Elaine's Realtime CRM Automation 6.18.17 - Reflected XSS
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex
33RISK
open ↗VulnCheck XDB
remote-with-credentials
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗VulnCheck XDB
client-side
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISK
open ↗VulnCheck XDB
initial-access
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open ↗GitHub PoC
A demo exploit for CVE-2021-44026, a SQL injection in Roundcube
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISK
open ↗GitHub PoC★ 9
WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISK
open ↗GitHub PoC
A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
corsisechero/CVE-2019-9193byVulHub
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open ↗GitHub PoC★ 1
mass scan for CVE-2025-30208
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.