Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,939cataloged exploits
32,191CVEs with public exploitation
1,932lab-tested
71,886 exploits
GitHub PoC
CVE-2025-29927-Nextjs 분석 보고서
CVE-2025-29927CRITICAL17 Mar 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
​Detailed analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362) for CS50 Cybersecurity. This project explores the technical impact of unauthenticated SQL Injection and its consequences for global data privacy, affecting 2,700+ organizations. Special thanks to Professor David J. Malan and the CS50 staff.
CVE-2023-34362CRITICALunder attackransomware17 Mar 2026
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
GitHub PoC
REC Exploit is a Python-based security testing tool that automates detection of potential RCE conditions in web applications under authorized environments. It sends crafted POST requests to targets, analyzes server responses for execution indicators, and supports batch scanning with custom input, structured payload handling, and clear CLI output.
CVE-2025-55182CRITICALunder attackransomware17 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2022-42889 취약점 분석보고서
CVE-2022-4288916 Mar 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
12-test-12/CVE-2025-3248
CVE-2025-3248CRITICALunder attackransomware16 Mar 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
CVE-2020-5902
CVE-2020-5902CRITICALunder attackransomware16 Mar 2026
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC
Proof-of-Concept exploit for Apache Struts S2-052 (CVE-2017-9805) XML Deserialization Remote Code Execution. Created while solving the INE eWPTX Practice Range lab. Includes custom payloads, reverse shell exploit script, and step-by-step exploitation examples.
CVE-2017-9805HIGHunder attack16 Mar 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC
Vulnerable Docker lab and exploit for Apache HTTP Server 2.4.49 path traversal vulnerability (CVE‑2021‑41773)
CVE-2021-41773HIGHunder attackransomware16 Mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware16 Mar 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9805HIGHunder attack16 Mar 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC
jgs-developer/CVE-2025-5548
CVE-2025-5548MEDIUM16 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
luisyapura/Analisis-y-Explotacion-de-CVE-2025-5548
CVE-2025-5548MEDIUM16 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
Diego57709/CVE-2025-5548
CVE-2025-5548MEDIUM16 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
Authenticated RCE in pgAdmin 4 (8.10–9.1) via eval() injection in the Query Tool. This is an updated PoC with compatibility fixes for pgAdmin 9.x auth changes
CVE-2025-2945CRITICAL16 Mar 2026
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISK
open
GitHub PoC
Binary exploitation laboratory: Environment setup and step-by-step walkthrough for exploiting CVE-2025-5548 using Ghidra, Immunity Debugger, and Python.
CVE-2025-5548MEDIUM16 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware16 Mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
POC for log4shll Vulnerablity (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware15 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Apache ActiveMQ OpenWire 역직렬화 RCE 취약점 기술 분석
CVE-2023-46604CRITICALunder attackransomware15 Mar 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
exploit para a CVE-2021-41773:Path Traversal cgi-bin
CVE-2021-41773HIGHunder attackransomware15 Mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
sumaiyafathima-code/CVE-2023-27524
CVE-2023-27524HIGHunder attack15 Mar 2026
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC
Laboratorio de análisis y explotación de la vulnerabilidad CVE-2025-5548 en FreeFloat FTP Server 1.0
CVE-2025-5548MEDIUM15 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
Victor875/CVE-2025-5548
CVE-2025-5548MEDIUM15 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC2
Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository documents vulnerability behavior, attack surface, controlled proof of concept testing, and defensive insights within a structured research environment for cybersecurity learning and analysis.
CVE-2025-5548MEDIUM15 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware15 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Script and node.proto for exploit CVE-2025-68926
CVE-2025-68926CRITICAL14 Mar 2026
RustFS has a gRPC Hardcoded Token Authentication Bypass
53RISK
open
GitHub PoC
anasrami12/CVE-2025-5548
CVE-2025-5548MEDIUM14 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
Heap Buffer Overflow in CVE-2025-5548
CVE-2025-5548MEDIUM14 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
Análisis técnico, preparación de entorno de laboratorio y desarrollo de exploit (RCE) para la vulnerabilidad CVE-2025-5548 en FreeFloat FTP Server.
CVE-2025-5548MEDIUM14 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
Explotación de la vulnerabilidad CVE-2025-5548, paso a paso
CVE-2025-5548MEDIUM14 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
previouspage 104 / 2,397next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.