Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
13,307 exploits
GitHub PoC1
🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For educational use only.[Made using Ai]
CVE-2025-29927CRITICAL06 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC3
ibrahmsql/CVE-2023-45131
CVE-2023-45131HIGH06 Jul 2025
Unauthenticated access to new private chat messages in Discourse
41RISK
open
GitHub PoC2
CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by default
CVE-2024-55963MEDIUM06 Jul 2025
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
38RISK
open
GitHub PoC1
An analysis and demonstration of the unauthenticated SQL Injection vulnerability (CVE-2022-3141) in ACS EDU 3rd Gen.
CVE-2022-314106 Jul 2025
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISK
open
GitHub PoC9
A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
r0otk3r/CVE-2025-3248
CVE-2025-3248CRITICALunder attackransomware06 Jul 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
hklabCR/CVE-2011-2523
CVE-2011-252306 Jul 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
CitrixBleed2 poc
CVE-2025-5777CRITICALunder attackransomware05 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC2
ibrahmsql/discourse-CVE-2021-41163
CVE-2021-41163CRITICAL05 Jul 2025
RCE via malicious SNS subscription payload
53RISK
open
GitHub PoC
Grafana RCE
CVE-2024-9264CRITICAL05 Jul 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC
Royall-Researchers/CVE-2025-24071
CVE-2025-24071MEDIUM05 Jul 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC3
cve-2025-32462' demo
CVE-2025-32462LOW05 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC3
ibrahmsql/CVE-2021-41163
CVE-2021-41163CRITICAL05 Jul 2025
RCE via malicious SNS subscription payload
53RISK
open
GitHub PoC
gmh5225/CVE-2025-6554
CVE-2025-6554HIGHunder attack05 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALunder attack05 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
r0otk3r/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
gmh5225/CVE-2025-6554-2
CVE-2025-6554HIGHunder attack05 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
GitHub PoC3
Memory disclosure vulnerability in Citrix NetScaler ADC and Gateway when configured as a Gateway (VPN virtual server, ICA proxy, CVPN, RDP Proxy).
CVE-2025-5777CRITICALunder attackransomware05 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC
Royall-Researchers/CVE-2024-9264
CVE-2024-9264CRITICAL05 Jul 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC
Papercut Vulnerability, Affected Versions are PaperCut MF or NG version 8.0 or later (excluding patched versions) on all OS platforms.
CVE-2023-27350CRITICALunder attackransomware05 Jul 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
Privilege escalation exploit for CVE-2025-32463 using a malicious NSS module injected via sudo -R. This version creates a stealth payload called illdeed, granting root access through a controlled chroot environment.
CVE-2025-32463CRITICALunder attack04 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC2
POC to exploit WordPress 5.6-5.7 (PHP 8+) Authenticated XXE Injection.
CVE-2021-29447HIGH04 Jul 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC1
CitrixBleed-2 (CVE-2025-5777) – proof-of-concept exploit for NetScaler ADC/Gateway “memory bleed”
CVE-2025-5777CRITICALunder attackransomware04 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC5
Unauthenticated Remote Code Execution exploit for CVE-2025-20281 in Cisco ISE ERS API. Execute commands or launch reverse shells as root — no authentication required.
CVE-2025-20281CRITICALunder attack04 Jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open
GitHub PoC8
🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers
CVE-2025-32462LOW04 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC1
CVE-2025-41646 - Critical Authentication bypass
CVE-2025-41646CRITICAL04 Jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RISK
open
GitHub PoC15
# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so
CVE-2025-32463CRITICALunder attack04 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
🛡️ Proof of Concept (PoC) for CVE-2025-32463 — Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational and authorized testing only.
CVE-2025-32463CRITICALunder attack04 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure token generation, SSL bypass, and improved output.
CVE-2024-4040CRITICALunder attack04 Jul 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
Remote Command Execution exploit for Wing FTP Server (CVE-2025-47812)
CVE-2025-47812CRITICALunder attack04 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
previouspage 138 / 444next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.