Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
13,282 exploits
GitHub PoC2
kindone09/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC7
CVE-2025-55182 React2Shell PoC lab
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC7
React2Shell vulnerability (CVE-2025-55182 / CVE-2025-66478)
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC12
This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React Server Components, also known as React2Shell.
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
this repo have CVE-2025-55182 full exploit with RCE
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC6
Header bypass for CVE-2025-55182 (React Server Components RCE).
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC8
StealthMoud/CVE-2025-55182-Scanner
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC4
React2Shell (CVE-2025-55182) Exploit
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the flag. Includes Nmap enumeration, Metasploit payload setup, and user hash cracking (John the Ripper).
CVE-2010-422105 Dec 2025
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RISK
open
GitHub PoC
Geoserver RCE
CVE-2024-36401CRITICALunder attack05 Dec 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
Arthurabriel/POC-CVE-2025-24813
CVE-2025-24813CRITICALunder attack05 Dec 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC2
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function.
CVE-2025-13486CRITICAL05 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC68
Next.js React Server Components RCE exploit for CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC139
Exploit for CVE-2025-55182 & CVE-2025-66478
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
selectarget/CVE-2025-55182-Exploit
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
topstar88/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells, countermeasures, and full command cheat-sheet.
CVE-2014-6271CRITICALunder attack05 Dec 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Webmin CGI Command Injection Remote Code Execution Vulnerability
CVE-2024-12828CRITICAL05 Dec 2025
Webmin CGI Command Injection Remote Code Execution Vulnerability
60RISK
open
GitHub PoC
Z3YR0xX/CVE-2025-64459
CVE-2025-64459CRITICAL05 Dec 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open
GitHub PoC
Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and defensive training in controlled lab environments only.
CVE-2021-44228CRITICALunder attackransomware05 Dec 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC117
Next.js-Exploit-Tool 图形化综合利用工具,基于 Go 开发,一款针对 CVE-2025-55182 的独立安全评估工具。
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2,451
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC5
POC for CVE-2025-13486
CVE-2025-13486CRITICAL04 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC
Docker test environment for CVE-2025-13486 (ACF Extended RCE). For security research only.
CVE-2025-13486CRITICAL04 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC
Vulnerable setup for CVE-2025-13486 - Advanced Custom Fields: Extended - Remote Code Execution
CVE-2025-13486CRITICAL04 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC4
xkillbit/cve-2025-55182-scanner
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
A proof of concept exploit script for CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
clevernyyyy/CVE-2025-55182-Dockerized
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
PoC CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
previouspage 103 / 443next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.