Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
72,018 exploits
GitHub PoC
Remake of CVE-2025-14847 MongoDB vulnerability demonstration
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471
CVE-2022-40471CRITICAL30 Dec 2025
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RISK
open
GitHub PoC2
Academic proof-of-concept demonstrating CVE-2025-68645 for authorized security research.
CVE-2025-68645HIGHunder attack30 Dec 2025
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
GitHub PoC
cve-2025-54236 poc
CVE-2025-54236CRITICALunder attack30 Dec 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
GitHub PoC
Udyz/CVE-2025-52691
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC2
AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433
CVE-2025-32433CRITICALunder attack29 Dec 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
Reproducible Docker lab for CVE-2018-15133 (Laravel Framework token unserialize RCE)
CVE-2018-15133HIGHunder attack29 Dec 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC4
Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
cv-sai-kamesh/n8n-CVE-2025-68613
CVE-2025-68613CRITICALunder attack29 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC3
CVE-2025-14847 (MongoBleed)
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847.
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
CVE-2025-14611 CentreStack and Triofox full Poc/Exploit
CVE-2025-14611HIGHunder attack29 Dec 2025
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RISK
open
GitHub PoC1
aexdyhaxor/CVE-2025-32463
CVE-2025-32463CRITICALunder attack29 Dec 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC13
Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Rishi-kaul/n8n-CVE-2025-68613
CVE-2025-68613CRITICALunder attack29 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC1
CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware29 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALunder attackransomware29 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC
amirali-ramezani/react2shell-CVE-2025-55182-
CVE-2025-55182CRITICALunder attackransomware29 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-14611HIGHunder attack29 Dec 2025
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack29 Dec 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC2
Proof of Concept for CVE-2025-24893 demonstrating unauthenticated remote command execution in XWiki through unsafe server-side template evaluation.
CVE-2025-24893CRITICALunder attack28 Dec 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack28 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack28 Dec 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
previouspage 138 / 2,401next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.