Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,304cataloged exploits
34,831CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,876VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
76,107 exploits
GitHub PoC★ 2
next.js CVE-2025-29927 vulnerability exploit
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 1
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 248
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISK
open ↗GitHub PoC★ 2
EPICOR HCM Unauthenticated Blind SQL Injection CVE-2025-22953
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HC
48RISK
open ↗GitHub PoC★ 4
PoC of CVE-2025-1974, modified from the world-first PoC~
ingress-nginx admission controller RCE escalation
85RISK
open ↗GitHub PoC
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
ingress-nginx admission controller RCE escalation
85RISK
open ↗GitHub PoC★ 1
yugo-eliatrope/test-cve-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
ingress-nginx admission controller RCE escalation
85RISK
open ↗VulnCheck XDB
infoleak
WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability
56RISK
open ↗GitHub PoC★ 97
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
ingress-nginx admission controller RCE escalation
85RISK
open ↗GitHub PoC★ 2
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
Next.js Acceso no autorizado CVE-2025-29927
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC★ 8
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
Detection and exploitation scripts for CVE-2024-4956
Nexus Repository 3 - Path Traversal
61RISK
open ↗GitHub PoC★ 1
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
48RISK
open ↗Exploit-DB
NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RISK
open ↗GitHub PoC
PoC
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.