Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
76,313 exploits
VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
initial-access
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open ↗VulnCheck XDB
initial-access
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗VulnCheck XDB
client-side
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗VulnCheck XDB
initial-access
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RISK
open ↗VulnCheck XDB
initial-access
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗GitHub PoC★ 10
XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗GitHub PoC★ 21
JSONPath-plus Remote Code Execution
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input
68RISK
open ↗GitHub PoC★ 3
WP Load Gallery <= 2.1.6 - Authenticated (Author+) Arbitrary File Upload
WordPress WP Load Gallery Plugin <= 2.1.6 - Arbitrary File Upload vulnerability
48RISK
open ↗GitHub PoC
A Rust exploit for CVE-2024-23346 that functions as a "terminal" (tested on chemistry.htb)
pymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
48RISK
open ↗GitHub PoC
Code to exploit CVE-2021-4034
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗GitHub PoC★ 1
Copy of the POC for CVE-2023-1545
SQL Injection in nilsteampassnet/teampass
41RISK
open ↗GitHub PoC★ 3
shishirghimir/CVE-2024-53677-Exploit
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RISK
open ↗GitHub PoC★ 4
numanturle/CVE-2025-25279
Arbitrary file read in Mattermost Boards via import & export board archive
53RISK
open ↗GitHub PoC
vivigotnotime/CVE-2023-22515-Exploit-Script
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗VulnCheck XDB
local
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗VulnCheck XDB
initial-access
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗GitHub PoC★ 2
cesarbtakeda/7-Zip-CVE-2025-0411-POC
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open ↗GitHub PoC★ 1
WordPress CVE-2024-10924 Exploit for Really Simple Security plugin
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open ↗GitHub PoC
WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
WinVerifyTrust Signature Validation Vulnerability
75RISK
open ↗VulnCheck XDB
initial-access
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open ↗GitHub PoC
Example usage: exploit.sh http://site.com
SQL Injection in nilsteampassnet/teampass
41RISK
open ↗GitHub PoC★ 4
CVE-2023-1698 Proof of Concept (PoC)
WAGO: WBM Command Injection in multiple products
85RISK
open ↗GitHub PoC★ 1
CVE-2025-24016: RCE in Wazuh server! Remote Code Execution
Remote code execution in Wazuh server
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.