Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
71,957 exploits
VulnCheck XDB
initial-access
CVE-2009-226512 Jan 2026
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALunder attack12 Jan 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISK
open
GitHub PoC2
CVE-2025-14847 | MongoBleed vulnerability proof of concept project
CVE-2025-14847HIGHunder attack12 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC3
CVE-2025-52694 Critical SQL Injection in Advantech IoTSuite/SaaS-Composer
CVE-2025-52694CRITICAL12 Jan 2026
Execution of arbitrary SQL commands
75RISK
open
GitHub PoC
Mr-In4inci3le/CVE-2025-11953-POC-
CVE-2025-11953CRITICALunder attack12 Jan 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISK
open
GitHub PoC
posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)
CVE-2009-226512 Jan 2026
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
GitHub PoC
sahar042/CVE-2025-14847
CVE-2025-14847HIGHunder attack11 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC3
rimbadirgantara/CVE-2025-52691-poc
CVE-2025-52691CRITICALunder attackransomware11 Jan 2026
Upload Arbitrary Files
100RISK
open
GitHub PoC1
Defensive PowerShell tool for static inspection of RAR archives and detection of CVE-2025-8088 path traversal anomalies.
CVE-2025-8088HIGHunder attack11 Jan 2026
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC1
PoC Authentication Bypass to RCE to Exploit CVE-2025-31161
CVE-2025-31161CRITICALunder attackransomware11 Jan 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC2
CVE-2025-55182漏洞检测工具
CVE-2025-55182CRITICALunder attackransomware11 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware11 Jan 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-52691CRITICALunder attackransomware11 Jan 2026
Upload Arbitrary Files
100RISK
open
GitHub PoC
js2py <= 0.74 sandbox escape (CVE-2024-28397)
CVE-2024-28397MEDIUM11 Jan 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-29059MEDIUM11 Jan 2026
Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly
48RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack11 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
comerc/CVE-2025-68664
CVE-2025-68664CRITICAL10 Jan 2026
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
53RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware10 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.
CVE-2024-5153CRITICAL10 Jan 2026
Startklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory Deletion
48RISK
open
GitHub PoC
Original security research into container boundary weaknesses. Published: OCI hook privilege escalation in rootless Podman deployments (CVE-2025-23266).
CVE-2025-23266CRITICAL10 Jan 2026
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISK
open
GitHub PoC
mooowu/cve-2025-55182-poc
CVE-2025-55182CRITICALunder attackransomware10 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS) vulnerabilities.
CVE-2024-6297CRITICAL10 Jan 2026
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
48RISK
open
GitHub PoC
Unauthenticated RCE exploit for XWiki CVE-2025-24893 via Groovy script injection
CVE-2025-24893CRITICALunder attack09 Jan 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-23397CRITICALunder attack09 Jan 2026
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
CVE-2015-3224 Exploit - Rails Web Console RCE
CVE-2015-322409 Jan 2026
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISK
open
GitHub PoC1
CVE-2025-14847 explaination and lab
CVE-2025-14847HIGHunder attack09 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE via service backdoors (CVE-2011-2523), and cryptographic credential recovery.
CVE-2011-252309 Jan 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC1
Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.
CVE-2023-23397CRITICALunder attack09 Jan 2026
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC
A drop-in fix for CVE-2023-29689 - SSTI in PyroCMS, via a custom Twig Sandbox implementation
CVE-2023-2968909 Jan 2026
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RISK
open
previouspage 131 / 2,399next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.