Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
72,018 exploits
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack22 Dec 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware22 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware22 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-1026HIGH22 Dec 2025
Kyocera Net View Address Book Exposure
61RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware22 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Vuln lab for CVE-2024-3408 - D-Tale Authentication Bypass & RCE
CVE-2024-3408CRITICAL22 Dec 2025
Authentication Bypass and RCE in man-group/dtale
85RISK
open
GitHub PoC1
Exploit Code for React2Shell RCE vulnerability (CVE-2025-55182) affecting React Server Components 19.0.0-19.2.0. Exploits unsafe deserialization for unauthenticated remote code execution.
CVE-2025-55182CRITICALunder attackransomware22 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
React2Shell Critical Vulnerability (CVE-2025-55182)
CVE-2025-55182CRITICALunder attackransomware22 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Spring4Shell
CVE-2022-22965CRITICALunder attack22 Dec 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC10
React2Shell: An exploitation framework for CVE-2025-55182 (Next.js/React RCE).
CVE-2025-55182CRITICALunder attackransomware22 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC25
Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance.
CVE-2025-68613CRITICALunder attack22 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC
Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.
CVE-2011-252322 Dec 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
CVE-2025-68613
CVE-2025-68613CRITICALunder attack22 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC1
Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021-43798)
CVE-2021-43798HIGHunder attack22 Dec 2025
Grafana path traversal
100RISK
open
GitHub PoC98
CVE-2025-68613: n8n RCE vulnerability exploit and documentation
CVE-2025-68613CRITICALunder attack22 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC6
A C++ security scanner tool to detect Cross-Site Scripting (XSS) vulnerabilities in Roundcube Webmail installations.
CVE-2025-68461HIGHunder attack22 Dec 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RISK
open
GitHub PoC28
Detection for CVE-2025-68613
CVE-2025-68613CRITICALunder attack22 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack22 Dec 2025
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3408CRITICAL22 Dec 2025
Authentication Bypass and RCE in man-group/dtale
85RISK
open
VulnCheck XDB
local
CVE-2025-38352HIGHunder attack21 Dec 2025
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
GitHub PoC
Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)
CVE-2025-64446CRITICALunder attack21 Dec 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
nicolasdamians/ms09-050-CVE-2009-3103-exploit
CVE-2009-310321 Dec 2025
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open
GitHub PoC4
Hello friend. This is the Fsociety Exploit Framework for CVE-2025-24071. Generates malicious .library-ms files to steal NTLMv2 hashes. Includes a 'Living Terminal' Cinematic Mode, Deep Trace logging, and stealth evasion techniques. Join the revolution. #Hacking #Exploit #CVE-2025-24071
CVE-2025-24071MEDIUM21 Dec 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC1
PoC exploit for CVE-2018-11736 affecting Pluck CMS versions prior to 4.7.7-dev2 with a File Upload Vulnerability
CVE-2018-1173621 Dec 2025
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute a
23RISK
open
GitHub PoC106
This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin mentions that this vulnerability has been used in limited, targeted exploitation in the wild.
CVE-2025-38352HIGHunder attack21 Dec 2025
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
VulnCheck XDB
infoleak
CVE-2025-55182CRITICALunder attackransomware21 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware21 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM21 Dec 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions
CVE-2025-55182CRITICALunder attackransomware21 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2023-32315(java7)
CVE-2023-32315HIGHunder attack21 Dec 2025
Openfire administration console authentication bypass
100RISK
open
previouspage 143 / 2,401next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.