Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
76,304 exploits
GitHub PoC★ 35
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open ↗GitHub PoC★ 25
A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open ↗Exploit-DB
MoziloCMS 3.0 - Remote Code Execution (RCE)
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISK
open ↗GitHub PoC
CVE-2025-30208 检测工具。python script && nuclei template
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗GitHub PoC★ 10
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗GitHub PoC★ 2
Next.js CVE-2025-29927 Vulnerability Scanner
Authorization Bypass in Next.js Middleware
85RISK
open ↗GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗GitHub PoC★ 3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open ↗GitHub PoC
liemkaka/CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open ↗GitHub PoC★ 4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open ↗GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open ↗VulnCheck XDB
initial-access
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open ↗GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗VulnCheck XDB
client-side
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take
53RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.