Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,451Referência 22,266GitHub PoC 14,131VulnCheck XDB 8,635Nuclei 4,274Metasploit 3,474✓ verified onlyrecentpopularrisk
77,151 exploits
VulnCheck XDB
local
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗VulnCheck XDB
initial-access
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗VulnCheck XDB
initial-access
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open ↗VulnCheck XDB
initial-access
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
41RISK
open ↗GitHub PoC
muhammad1596/CVE-2022-0847-DirtyPipe-Exploits
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC★ 9
CVE-2024-4956 Python exploitation utility
Nexus Repository 3 - Path Traversal
61RISK
open ↗VulnCheck XDB
infoleak
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
68RISK
open ↗GitHub PoC
CVE-2017-8917 SQL injection Vulnerability in Joomla! 3.7.0 exploit
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RISK
open ↗GitHub PoC★ 26
Sk1dr0wz/CVE-2024-4358_Mass_Exploit
Registration Authentication Bypass Vulnerability
100RISK
open ↗GitHub PoC
This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps.
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open ↗GitHub PoC
CVE-2021-1675/CVE-2021-34527 PrintNightmare & CVE-2020-0668
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open ↗GitHub PoC★ 1
Oracle WebLogic Server (LFI)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open ↗VulnCheck XDB
local
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open ↗GitHub PoC★ 1
muhammad1596/CVE-2022-0847-dirty-pipe-checker
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗VulnCheck XDB
initial-access
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and
78RISK
open ↗GitHub PoC★ 2
Precompiled binaries for Privilege Escalation in Oracle VM Virtual box prior to 7.0.16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
41RISK
open ↗Metasploit300
Telerik Report Server Auth Bypass
Registration Authentication Bypass Vulnerability
100RISK
open ↗GitHub PoC★ 5
An Vulnerability detection and Exploitation tool for CVE-2024-4358
Registration Authentication Bypass Vulnerability
100RISK
open ↗Metasploit600
Telerik Report Server Auth Bypass and Deserialization RCE
Progress Telerik Report Server Deserialization
55RISK
open ↗Metasploit600
Telerik Report Server Auth Bypass and Deserialization RCE
Registration Authentication Bypass Vulnerability
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.