Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
72,018 exploits
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack23 Dec 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware23 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213
CVE-2025-66209CRITICAL23 Dec 2025
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup
48RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack23 Dec 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC
machevalia/CVE-2025-14733
CVE-2025-14733CRITICALunder attack23 Dec 2025
WatchGuard Firebox iked Out of Bounds Write Vulnerability
83RISK
open
GitHub PoC
CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation modules, stealth capabilities, and comprehensive documentation. For authorized testing only.
CVE-2021-3493HIGHunder attack23 Dec 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
GitHub PoC
nulltrace1336/Samba-Exploit-CVE-2007-2447
CVE-2007-244723 Dec 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC146
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
CVE-2025-54068CRITICALunder attack23 Dec 2025
Livewire vulnerable to remote command execution during property update hydration
100RISK
open
GitHub PoC
POC for CVE-2025-68613
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC
My poc to exploit this vuln :D
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC
通过GitHub Copilot 辅助分析CVE-2025-68613漏洞
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC
a controlled environment to test CVE-2025-55182.
CVE-2025-55182CRITICALunder attackransomware23 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
js2py sandbox escape to reverse shell
CVE-2024-39205CRITICAL23 Dec 2025
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a
68RISK
open
GitHub PoC
Ushbu videoda Metasploitable 2 tizimidagi distccd servisidagi zaiflikdan foydalanib, Kali Linux orqali remote shell olish ko‘rsatib beriladi.
CVE-2004-268723 Dec 2025
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open
GitHub PoC
This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**.
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC
ali-py3/Exploit-CVE-2025-68613
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC2
CVE-2025-62215: Windows Kernel Race Condition + Double-Free EoP
CVE-2025-62215HIGHunder attack23 Dec 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
CVE-2025-14558
CVE-2025-14558HIGH23 Dec 2025
Remote code execution via ND6 Router Advertisements
56RISK
open
GitHub PoC
PoC for HTTP/2 Rapid Reset DDoS Vulnerability - CVE-2023-44487
CVE-2023-44487HIGHunder attack23 Dec 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC6
RCE exploit PoC for CVE-2025-55182 and CVE-2025-66478 in Next.js and React Server Components with scanner and exploitation tools.
CVE-2025-55182CRITICALunder attackransomware23 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Instructions for rapid deployment of Tomcat v9.0.90 with java 25.0.1 2025-10-21 LTS on Windows Server 2019 Standard for lazy researchers.
CVE-2025-24813CRITICALunder attack23 Dec 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack23 Dec 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54068CRITICALunder attack23 Dec 2025
Livewire vulnerable to remote command execution during property update hydration
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack23 Dec 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
local
CVE-2025-62215HIGHunder attack23 Dec 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack22 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-33045CRITICALunder attack22 Dec 2025
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack22 Dec 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
previouspage 142 / 2,401next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.