Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
75,589 exploits
VulnCheck XDB
initial-access
CVE-2017-1261115 Sep 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISK
open
GitHub PoC
tranphuc2005/CVE-2017-9822
CVE-2017-9822HIGHunder attackransomware15 Sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISK
open
GitHub PoC
Authentication bypass vulnerability in versions of the CrushFTP server.
CVE-2025-31161CRITICALunder attackransomware15 Sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC
tcetin704/CVE-2017-12611
CVE-2017-1261115 Sep 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware15 Sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC2
Langflow Remote Code Execution
CVE-2025-3248CRITICALunder attackransomware15 Sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
local
CVE-2025-48543HIGHunder attack14 Sep 2025
In multiple locations, there is a possible way to escape chrome sandbox to attack android system_server due to a use aft
71RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack14 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALunder attack14 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3_2_1_fixed
CVE-2023-49109CRITICAL14 Sep 2025
Remote Code Execution in Apache Dolphinscheduler
48RISK
open
GitHub PoC1
Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-parameter verdicts and JSON reporting.
CVE-2025-57819CRITICALunder attack14 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC
Documented CVE-2021-41773 (Apache HTTP Server path traversal, CVSS 9.8) — produced CVSS breakdown, impact assessment, and a mitigation plan (patch to 2.4.51+, CGI disable, firewall) and published the analysis on GitHub.
CVE-2021-41773HIGHunder attackransomware14 Sep 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
A proof-of-concept exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower. This tool creates a malicious RAR archive that embeds payloads in Alternate Data Streams (ADS) with path traversal, potentially leading to arbitrary code execution.
CVE-2025-8088HIGHunder attack14 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
Shubhankargupta691/CVE-2024-42009
CVE-2024-42009CRITICALunder attack14 Sep 2025
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
GitHub PoC7
Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL13 Sep 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISK
open
GitHub PoC
chin-tech/CrushFTP_CVE-2025-54309
CVE-2025-54309CRITICALunder attack13 Sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
GitHub PoC
CVE-2025-48384-submodule
CVE-2025-48384HIGHunder attack13 Sep 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
Grafana SQL Expressions → DuckDB LFI (CVE-2024-9264)
CVE-2024-9264CRITICAL13 Sep 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack13 Sep 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack13 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC1
Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.
CVE-2007-244713 Sep 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware13 Sep 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack13 Sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
VulnCheck XDB
local
CVE-2021-3493HIGHunder attack13 Sep 2025
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
Metasploit600
Flowise JS Injection RCE
CVE-2025-59528CRITICAL13 Sep 2025
Flowise has Remote Code Execution vulnerability
85RISK
open
GitHub PoC2
CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain attack affecting Linux systems, highlighting risks in trusted open-source components.
CVE-2024-3094CRITICAL12 Sep 2025
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALunder attack12 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
client-side
CVE-2025-4123HIGH12 Sep 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
GitHub PoC4
Ash1996x/CVE-2025-54914-PoC
CVE-2025-54914CRITICAL12 Sep 2025
Azure Networking Elevation of Privilege Vulnerability
48RISK
open
GitHub PoC6
FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.
CVE-2025-57819CRITICALunder attack12 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
previouspage 202 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.