Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
76,313 exploits
VulnCheck XDB
initial-access
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor
56RISK
open ↗VulnCheck XDB
remote-with-credentials
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open ↗VulnCheck XDB
infoleak
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open ↗GitHub PoC
Project on CVE-2022-30190 exploitation and mitigation strategies
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open ↗Metasploit300
Xorcom CompletePBX Authenticated File Disclosure via Backup Download
Xorcom CompletePBX <= 5.2.35 Authenticated File Disclosure
28RISK
open ↗Metasploit300
Xorcom CompletePBX Arbitrary File Read and Deletion via systemDataFileName
Xorcom CompletePBX <= 5.2.35 Authenticated Path Traversal & File Deletion
36RISK
open ↗Metasploit600
Xorcom CompletePBX Authenticated Command Injection via Task Scheduler
Xorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection
36RISK
open ↗GitHub PoC★ 3
Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open ↗GitHub PoC
GazettEl/CVE-2020-17519
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open ↗GitHub PoC★ 129
Deterministic kernel exploit based on CVE-2023-32434.
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISK
open ↗VulnCheck XDB
local
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISK
open ↗VulnCheck XDB
initial-access
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open ↗VulnCheck XDB
initial-access
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open ↗GitHub PoC★ 1
overgrowncarrot1/CVE-2019-1003030
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open ↗GitHub PoC
CVE-2019-18935: Remote Code Execution
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open ↗GitHub PoC★ 4
Mautic < 5.2.3 Authenticated RCE
Remote Code Execution & File Deletion in Asset Uploads
48RISK
open ↗GitHub PoC★ 1
skrkcb2/CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗VulnCheck XDB
initial-access
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open ↗VulnCheck XDB
initial-access
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open ↗GitHub PoC★ 232
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC
cojoben/CVE-2018-13382
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open ↗GitHub PoC★ 6
CVE-2025-26263 - GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISK
open ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
initial-access
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open ↗GitHub PoC
Automation script to exploit the Shellshock vulnerability.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
client-side
WordPress Essential Addons for Elementor plugin <= 6.0.14 - Reflected Cross Site Scripting (XSS) vulnerability
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.