Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
13,307 exploits
GitHub PoC2
CyberQuestor-infosec/CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE
CVE-2021-41773HIGHunder attackransomware11 Jun 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC6
A PoC exploit for CVE-2017-9841 - PHPUnit Remote Code Execution(RCE)
CVE-2017-9841CRITICALunder attack10 Jun 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC2
Detection for CVE-2025-24016 - Deserialization of Untrusted Data Vulnerability in the Wazuh software
CVE-2025-24016CRITICALunder attack10 Jun 2025
Remote code execution in Wazuh server
100RISK
open
GitHub PoC
CVE-2025-24071
CVE-2025-24071MEDIUM10 Jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC6
Proof-of-concept to CVE-2025-49113
CVE-2025-49113CRITICALunder attack10 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
CVE-2025-32756: NSE Scanning for RCE in vulnerable FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera nodes
CVE-2025-32756CRITICALunder attack09 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open
GitHub PoC
alm6no5/CVE-2025-32756-POC
CVE-2025-32756CRITICALunder attack09 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open
GitHub PoC
Arshit01/CVE-2023-20198
CVE-2023-20198CRITICALunder attack09 Jun 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC3
Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability
CVE-2025-24071MEDIUM09 Jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins, extracting SYSTEM and SAM hives for local NTLM hashes.
CVE-2021-36934HIGHunder attack09 Jun 2025
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC1
CVE-2025-29927 - Critical Security Vulnerability in Next.js
CVE-2025-29972CRITICAL09 Jun 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RISK
open
GitHub PoC
CVE-2021-3156-Exploit-Demo
CVE-2021-3156HIGHunder attack09 Jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
CVE-2024-10914CRITICAL09 Jun 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC2
This script exploits CVE-2025-49619 in Skyvern to execute a reverse shell command.
CVE-2025-49619HIGH09 Jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RISK
open
GitHub PoC
Atlassian's Confluence Server and Data Center editions (Vulnerable Version > 7.18.1)
CVE-2022-26134CRITICALunder attackransomware09 Jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
CyberBibs/Event-ID-263-Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-
CVE-2024-24919HIGHunder attackransomware08 Jun 2025
Information disclosure
100RISK
open
GitHub PoC
CVE-2025-0282
CVE-2025-0282CRITICALunder attackransomware08 Jun 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
GitHub PoC
CyberBibs/SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-
CVE-2024-3400CRITICALunder attackransomware08 Jun 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
CVE-2024-40453 - Squirrelly v9.0.0 RCE. Poc
CVE-2024-40453CRITICAL08 Jun 2025
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the com
48RISK
open
GitHub PoC
CVE-2024-51482 ZoneMinder v1.37.* <= 1.37.64 poc
CVE-2024-51482CRITICAL07 Jun 2025
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC
CVE-2025-31131
CVE-2025-31131HIGH07 Jun 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RISK
open
GitHub PoC1
CVE-2017-5638 Exploit Rewritten In Python By haxerr9
CVE-2017-5638CRITICALunder attackransomware07 Jun 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
CVE-2025-31161
CVE-2025-31161CRITICALunder attackransomware07 Jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC18
mbanyamer/CVE-2025-24076
CVE-2025-24076HIGH06 Jun 2025
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
POC
CVE-2025-30208MEDIUM06 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
🚨 Exploit CVE-2025-55182 to demonstrate RCE in React Server Functions, highlighting risks from insecure prototype references in Next.js applications.
CVE-2025-55182CRITICALunder attackransomware06 Jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
CVE-2025-49113 exploit
CVE-2025-49113CRITICALunder attack06 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC90
Proof of Concept demonstrating Remote Code Execution through insecure deserialization in Roundcube (CVE-2025-49113).
CVE-2025-49113CRITICALunder attack06 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
This is a little Python script to detect the "EvilSun" vulnerability (CVE-2020-14871) on Solaris systems. The vulnerability is a buffer overflow in the Pluggable Authentication Module (PAM) `pam_unix_auth` when handling keyboard-interactive authentication in SSH.
CVE-2020-14871CRITICALunder attack06 Jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
GitHub PoC1
CyberQuestor-infosec/CVE-2022-46604-Responsive-File-Manager
CVE-2022-46604HIGH05 Jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISK
open
previouspage 144 / 444next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.