Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
13,282 exploits
GitHub PoC1
Proof-of-Concept RCE pour CVE‑2025‑55182 exploitant le protocole React Flight sur Next.js App Router.
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
React2Shell (CVE-2025-55182) – An intentionally vulnerable Next.js application created for educational and research purposes.
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC26
使用burp自动检测CVE-2025-55182 Next.js RCE 漏洞
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Proof of Concept for React2Shell vulnerability
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
PoC for React2Shell (CVE-2025-55182)
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Show case CVE-2025-55182 POC in Typrescript/Javascript
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2025-55182 Interactive PoC - React Server Components RCE - Educational Security Research
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
GarethMSheldon/React2Shell-CVE-2025-55182-Detector
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
kindone09/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC7
CVE-2025-55182 React2Shell PoC lab
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC7
React2Shell vulnerability (CVE-2025-55182 / CVE-2025-66478)
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC6
Header bypass for CVE-2025-55182 (React Server Components RCE).
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC29
Working proof of concept for NextJS RCE to establish a reverse shell. [React2Shell]
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells, countermeasures, and full command cheat-sheet.
CVE-2014-6271CRITICALunder attack05 Dec 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC2
"One crafted HTTP request can compromise your entire server." — React Security Team, Dec 2025
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC65
An analysis of CVE-2025-55182 and CVE-2025-66478 -- the vulnerabilities behind React2Shell. Tools, technical information, etc
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
A containerized testing environment for CVE-2025-55182, a critical (10.0 CVSS) Remote Code Execution vulnerability in React Server Components.
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC86
Docker poc lab for CVE-2025-55182 / CVE-2025-66478 (React2Shell) detection and exploitation
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
浅谈React Server Components RCE 漏洞分析
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC8
StealthMoud/CVE-2025-55182-Scanner
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC10
React Server Components 远程代码执行漏洞(CVE-2025-55182)
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Interactive RCE Web Shell (CVE-2025-55182) BY Golden-Security
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Webmin CGI Command Injection Remote Code Execution Vulnerability
CVE-2024-12828CRITICAL05 Dec 2025
Webmin CGI Command Injection Remote Code Execution Vulnerability
60RISK
open
GitHub PoC4
Lightweight scanner and Nuclei templates for identifying React and Next.js deserialization RCEs (CVE-2025-55182 / CVE-2025-66478).
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
alexandre-briongos-wavestone/react-cve-2025-55182-lab
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Geoserver RCE
CVE-2024-36401CRITICALunder attack05 Dec 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and defensive training in controlled lab environments only.
CVE-2021-44228CRITICALunder attackransomware05 Dec 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 102 / 443next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.