Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
13,307 exploits
GitHub PoC
Documentation for CVE-2025-6514. MCP-Remote RCE.
CVE-2025-6514CRITICAL11 Jul 2025
OS command injection in mcp-remote when connecting to untrusted MCP servers
70RISK
open
GitHub PoC
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros
CVE-2025-32462LOW11 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC
Rust PoC for CVE-2025-32463 (sudo chroot "chwoot" Local PrivEsc)
CVE-2025-32463CRITICALunder attack11 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
cuijiung/log4j-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
hackmelocal/CVE-2025-49113-Simulation
CVE-2025-49113CRITICALunder attack11 Jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
just remeber how small mistake in santisize username could give yoy root access to the full machine
CVE-2007-244711 Jul 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
r0otk3r/CVE-2024-10915
CVE-2024-10915CRITICAL11 Jul 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
r0otk3r/CVE-2024-25600
CVE-2024-25600CRITICAL10 Jul 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
Praktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)
CVE-2021-44228CRITICALunder attackransomware10 Jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
r0otk3r/CVE-2024-27954
CVE-2024-27954CRITICAL10 Jul 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
85RISK
open
GitHub PoC
CVE-2025-6554 PoC
CVE-2025-6554HIGHunder attack10 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
GitHub PoC18
CVE-2025-6218 is a directory traversal vulnerability in WinRAR that allows an attacker to place files outside the intended extraction directory when a user extracts a specially crafted
CVE-2025-6218HIGHunder attack10 Jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
GitHub PoC98
watchtowrlabs/watchTowr-vs-FortiWeb-CVE-2025-25257
CVE-2025-25257CRITICALunder attack10 Jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
GitHub PoC
greatyy/CVE-2025-48384-p
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
CVE-2025-48384
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
漏洞测试
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
altm4n/cve-2025-48384
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
altm4n/cve-2025-48384-hub
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC14
This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a Windows 10 machine within a finance-oriented infrastructure.
CVE-2017-0144HIGHunder attackransomware10 Jul 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
Exploit for CVE-2025-32023
CVE-2025-32023HIGH10 Jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RISK
open
GitHub PoC
Citrix NetScaler Memory Leak PoC
CVE-2025-5777CRITICALunder attackransomware10 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC30
CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)
CVE-2025-5777CRITICALunder attackransomware10 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC8
ekkoo-z/CVE-2019-18935-bypasswaf
CVE-2019-18935CRITICALunder attackransomware09 Jul 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
CitrixBleed2 powershell version
CVE-2025-5777CRITICALunder attackransomware09 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC
kallydev/cve-2025-48384-hook
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC21
PoC for CVE-2025-48384
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
liamg/CVE-2025-48384-submodule
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
fishyyh/CVE-2025-48384-POC
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
for CVE-2025-48384 test
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
ppd520/CVE-2025-48384
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
previouspage 136 / 444next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.