Sploitus
The only capture we hold is a challenge page, not the service. It is kept for evidence but is not shown here as if it were the site. View the raw capture.
π Sploitus | Exploit & Hacktool Search Engine
Sploitus is a convenient central place for identifying the newest exploits and finding attacks that exploit known vulnerabilities. The search engine is also a good resource for finding security and vulnerability discovery tools.
Skip to main content SPLOITUS Exploits Tools Relevance Date Score Search by CVE identifier, product name, exploit or security tool Search engine for exploits and hacktools: proof-of-concept code, CVEs and the products they affect β collected from across the internet, all in one place. Trending CVEs Recent vulnerabilities with available exploits CVE-2026-58644 1 exploit CRITICAL 9.8 Microsoft Sharepoint Server 2026-07-14 CVE-2026-33824 2 exploits CRITICAL 9.8 Microsoft Windows 10 2026-04-14 CVE-2025-62593 1 exploit HIGH 8.8 Anyscale Ray 2025-11-14 CVE-2026-42980 1 exploit HIGH 7.8 Microsoftβ¦
| When | Status | HTTP | Response | Bytes | Via |
|---|---|---|---|---|---|
| 5m ago | Alive | 200 | 36 ms | 51,210 | chrome-stealth |
| 1h ago | Alive content moved | 200 | 23 ms | 51,210 | chrome-stealth |
| 2h ago | Alive content moved | 200 | 35 ms | 51,208 | chrome-stealth |
| 4h ago | Alive content moved | 200 | 24 ms | 51,244 | chrome-stealth |
| 6h ago | Alive | 200 | 25 ms | 51,073 | chrome-stealth |
- Csp
- Raw
default-src 'self' https: 'unsafe-inline'; img-src 'self' https: data:; connect-src 'self' https: wss://mc.yandex.ru- Directives
- Default src
- 'self'https:'unsafe-inline'
- Img src
- 'self'https:data:
- Connect src
- 'self'https:wss://mc.yandex.ru
- Unsafe inline
- yes
- Unsafe eval
- no
- Hsts
- Max age
31536000- Include subdomains
- yes
- Preload
- yes
- X frame options
SAMEORIGIN- X content type options
nosniff- Referrer policy
no-referrer-when-downgrade- Cross origin
- X xss protection
1; mode=block- Cookies
- Count
0- Secure
0- Httponly
0- Samesite
0
- Score
72- Missing
- permissions_policycoopcoepcorp
- Protocol
QUIC- Cipher
AES_128_GCM- Key exchange group
X25519MLKEM768- Signature algorithm
1027- Subject
sploitus.com- Issuer
WE1- San
- sploitus.com*.sploitus.com
- San count
2- Wildcard
- yes
- Valid from
2026-08-05 14:23:54- Valid to
2026-11-03 15:21:19- Days remaining
73- Self signed
- no
- Ct compliance
unknown- Ech
- no
- Server
- Raw
cloudflare- Name
cloudflare- Family
cloudflare
- Analytics
- Name
Google Analytics
- Name
Yandex Metrika
- Name
Cloudflare Insights
- Cdn
- Cloudflare
- Protocol
h3
- Detected
- yes
- Kind
cloudflare-interstitial- Vendor
Cloudflare- Label
Cloudflare JS challenge- Confidence
100- Signals
- served through CloudflareCloudflare challenge-platform scriptchallenge-platform asset path
- Self clearing
- yes
- Cleared
- no
- Waited ms
27269- Http code
200- Via
chrome-stealth
- Total
0
- Total
0
- Count
1- Kinds
- Search
1
- Has login
- no
- Has search
- yes
- Has upload
- no
- Forms
- Kind
search- Method
get- Action
https://sploitus.com/- Inputs
1- Types
- search
- Password
- no
- File
- no
-
onion_unique
not tracked
onion_unique -
onion_total
not tracked
onion_total -
clearnet_unique
not tracked
clearnet_unique2 -
internal
not tracked
internal24 -
external
not tracked
external2 -
total
not tracked
total32 -
truncated
not tracked
truncated
| Header | Value |
|---|---|
age |
811 |
alt-svc |
h3=":443"; ma=86400 |
cache-control |
public, max-age=0, s-maxage=900, stale-while-revalidate=3600 |
cf-cache-status |
HIT |
cf-ray |
a2eb83a11c1c0ee3-CPH |
content-encoding |
zstd |
content-security-policy |
default-src 'self' https: 'unsafe-inline'; img-src 'self' https: data:; connect-src 'self' https: wss://mc.yandex.ru |
content-type |
text/html; charset=UTF-8 |
date |
Fri, 21 Aug 2026 17:56:23 GMT |
last-modified |
Fri, 21 Aug 2026 17:56:23 GMT |
link |
</llms.txt>; rel="llms-txt" |
nel |
{"report_to":"cf-nel","success_fraction":0.0,"max_age":604800} |
priority |
u=0,i |
referrer-policy |
no-referrer-when-downgrade |
report-to |
{"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=2nhjAReLfKMXLPmws8QXxoioI4US532i7cWDIPDCkg6Ij4SI5%2FLZzYNqa%2FiAbZtQRygL2vQ%2B1WmJduAfBpSAv%2F6DMJWN%2BVY2FMtXAU%2FSdmW5D6qa2W5OIpigB%2F%2BwD%2Bs%3D"}]} |
server |
cloudflare |
server-timing |
cfCacheStatus;desc="HIT", cfEdge;dur=11,cfOrigin;dur=0, cfExtPri |
speculation-rules |
"/cdn-cgi/speculation" |
strict-transport-security |
max-age=31536000; includeSubDomains; preload |
vary |
Accept-Encoding |
x-content-type-options |
nosniff |
x-frame-options |
SAMEORIGIN |
x-xss-protection |
1; mode=block |