Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,899GitHub PoC 14,014VulnCheck XDB 8,571Nuclei 4,248Metasploit 3,472✓ verified onlyrecentpopularrisk
76,559 exploits
VulnCheck XDB
initial-access
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open ↗GitHub PoC
Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload
WordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability
48RISK
open ↗VulnCheck XDB
infoleak
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open ↗VulnCheck XDB
initial-access
Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movab
60RISK
open ↗GitHub PoC★ 14
Exploit for cve-2024-10914: D-Link DNS-320, DNS-320LW, DNS-325, DNS-340L Version 1.00, Version 1.01.0914.2012, Version 1.01, Version 1.02, Version 1.08 Command Injection
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open ↗GitHub PoC
WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion
WPLMS Learning Management System for WordPress <= 4.962 - Unauthenticated Arbitrary File Read and Deletion
60RISK
open ↗GitHub PoC
Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISK
open ↗GitHub PoC
CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation
63RISK
open ↗GitHub PoC
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload
WordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerability
48RISK
open ↗VulnCheck XDB
initial-access
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open ↗GitHub PoC★ 1
0xR00/CVE-2024-23334
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open ↗GitHub PoC
CVE-2023-25813 Vulnerability Reproduction - SQL Injection in Sequelize
SQL Injection via replacements in sequelize
48RISK
open ↗VulnCheck XDB
initial-access
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open ↗VulnCheck XDB
initial-access
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open ↗VulnCheck XDB
initial-access
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISK
open ↗GitHub PoC★ 98
Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open ↗GitHub PoC★ 1
cbyerpanel rce exploit
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas
100RISK
open ↗GitHub PoC★ 1
AliHj98/cve-2024-38063-Anonyvader
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC
Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open ↗GitHub PoC
pedrochalegre7/CVE-2024-4367-pdf-sample
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC★ 6
WP REST API FNS <= 1.0.0 - Privilege Escalation
WordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
48RISK
open ↗VulnCheck XDB
remote-with-credentials
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISK
open ↗GitHub PoC★ 3
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISK
open ↗GitHub PoC
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
WatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
48RISK
open ↗GitHub PoC★ 2
Meetup <= 0.1 - Authentication Bypass via Account Takeover
WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
48RISK
open ↗GitHub PoC
guigui237/Expoitation-de-la-vuln-rabilit-CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.