Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,016cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
13,320 exploits
GitHub PoC1
A XZ backdoor vulnerability explained in details
CVE-2024-3094CRITICAL03 Jun 2025
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Authenticated Remote Command Execution – pfSense <= 2.1.3
CVE-2014-468803 Jun 2025
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISK
open
GitHub PoC3
A reflected cross-site scripting (XSS) vulnerability exists in MailEnable Webmail due to improper user input sanitization in the failure.aspx. This allows a remote attacker to inject arbitrary JavaScript code via a crafted URL, which is then reflected in the server's response and executed in the context of the user's browser session.
CVE-2025-44148CRITICAL02 Jun 2025
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via
75RISK
open
GitHub PoC
MS08-067 | CVE-2008-4250
CVE-2008-4250CRITICALunder attack02 Jun 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
GitHub PoC3
CTY-Research-1/CVE-2025-32432-PoC
CVE-2025-32432CRITICALunder attack01 Jun 2025
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC2
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL01 Jun 2025
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
GitHub PoC1
fatkz/CVE-2025-27590
CVE-2025-27590CRITICAL31 May 2025
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr
53RISK
open
GitHub PoC
Vbullettin RCE - CVE-2025-48827
CVE-2025-48827CRITICAL31 May 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISK
open
GitHub PoC1
This Python script exploits CVE-2025-3248 to execute arbitrary commands or spawn a reverse shell on a vulnerable system. Authentication is required to use this exploit.
CVE-2025-3248CRITICALunder attackransomware31 May 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC3
A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.
CVE-2024-9264CRITICAL31 May 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC67
Remote Code Execution via Use-After-Free in JScript.dll (CVE-2025-30397)
CVE-2025-30397HIGHunder attack31 May 2025
Scripting Engine Memory Corruption Vulnerability
76RISK
open
GitHub PoC
davidxbors/CVE-2024-7399-POC
CVE-2024-7399HIGHunder attack30 May 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RISK
open
GitHub PoC
This script checks for the OpenSSH 7.7 (and prior) username enumeration vulnerability (CVE-2018-15473). It sends a malformed authentication packet and interprets the SSH server’s response to identify valid usernames.
CVE-2018-15473MEDIUM30 May 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC5
ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR
CVE-2021-26828HIGHunder attack30 May 2025
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISK
open
GitHub PoC
Automated bash script which scans an ip for potential vulnerability to eternalblue using nmap and then exploit using metasploit framework which uses the CVE-2017-0144 vulnerability[Code name: EternalBlue] in (windows 7,windows 2008 servers,etc.) to gain access to a windows 7 machine and establish a reverse meterpreter shell.
CVE-2017-0144HIGHunder attackransomware30 May 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC4
WordPress TI WooCommerce Wishlist Plugin <= 2.9.2 Arbitrary File Upload
CVE-2025-47577CRITICAL30 May 2025
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RISK
open
GitHub PoC
MQKGitHub/Moniker-Link-CVE-2024-21413
CVE-2024-21413CRITICALunder attack30 May 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC11
Critical Unauthenticated API Access in vBulletin
CVE-2025-48827CRITICAL29 May 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISK
open
GitHub PoC5
nkuty/CVE-2025-30208-31125-31486-32395
CVE-2025-30208MEDIUM29 May 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
thompson005/CVE-2023-22527
CVE-2023-22527CRITICALunder attackransomware29 May 2025
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
GitHub PoC
Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))
CVE-2021-2291129 May 2025
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL29 May 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
AzkOsDev/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware28 May 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC3
Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without user interaction. Responder captures the NTLM hash once the target accesses the library.
CVE-2025-24071MEDIUM28 May 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC2
Telerik CVE-2017-9248 Vulnerability Scanner
CVE-2017-9248CRITICALunder attack28 May 2025
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RISK
open
GitHub PoC1
Perform Remote Code Execution using vulnerable API endpoint.
CVE-2025-3248CRITICALunder attackransomware27 May 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC2
CVE-2025-24071 Proof Of Concept
CVE-2025-24071MEDIUM27 May 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
KimJuhyeong95/cve-2024-4577
CVE-2024-4577CRITICALunder attackransomware27 May 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Log4Shell (CVE-2021-44228) exploit demo for SEAS 8405. Includes a vulnerable Spring Boot app, fake LDAP server, Docker setup, MITRE mapping, incident response, and a full screen recording.
CVE-2021-44228CRITICALunder attackransomware27 May 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
UMChacker/CVE-2024-55591-POC
CVE-2024-55591CRITICALunder attackransomware26 May 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
100RISK
open
previouspage 146 / 444next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.