Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
75,589 exploits
VulnCheck XDB
infoleak
CVE-2017-18362CRITICALunder attackransomware14 Aug 2025
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware14 Aug 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
okkotsu1/CVE-2024-47533
CVE-2024-47533CRITICAL14 Aug 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open
Metasploit600
Flowise Custom MCP Remote Code Execution
CVE-2025-8943CRITICAL14 Aug 2025
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
65RISK
open
GitHub PoC
Dissecting CVEin Chrome
CVE-2025-5419HIGHunder attack13 Aug 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISK
open
GitHub PoC1
PoC of CVE-2025-47533 Clobber RCE
CVE-2024-47533CRITICAL13 Aug 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open
GitHub PoC
oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙
CVE-2023-32434HIGHunder attack13 Aug 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISK
open
GitHub PoC
Proof of concept for the vulnerability CVE-2025-50428: Authenticated OS Command Injection in RaspAP
CVE-2025-50428CRITICAL13 Aug 2025
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script.
48RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack13 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack13 Aug 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-24054MEDIUMunder attack13 Aug 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC3
zenzue/CVE-2025-50154
CVE-2025-50154MEDIUM13 Aug 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack13 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
client-side
CVE-2017-11882HIGHunder attackransomware13 Aug 2025
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
PoC exploit for XWiki Remote Code Execution Vulnerability (CVE-2025-24893)
CVE-2025-24893CRITICALunder attack13 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC55
POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch
CVE-2025-50154MEDIUM13 Aug 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC71
CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)
CVE-2025-8088HIGHunder attack13 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC7
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433
CVE-2025-32433CRITICALunder attack13 Aug 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack13 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
CyprianAtsyor/ToolShell-CVE-2025-53770-SharePoint-Exploit-Lab-LetsDefend
CVE-2025-53770CRITICALunder attackransomware13 Aug 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
benguelmas/cve-2017-0143
CVE-2017-0143HIGHunder attackransomware13 Aug 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
Berisi 2 program C dari exploitDB untuk melakukan privillage eskalation untuk ubuntu 16.04
CVE-2017-1699512 Aug 2025
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RISK
open
GitHub PoC8
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.
CVE-2024-47533CRITICAL12 Aug 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware12 Aug 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware12 Aug 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-25231HIGH12 Aug 2025
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga
61RISK
open
VulnCheck XDB
infoleak
CVE-2025-53770CRITICALunder attackransomware12 Aug 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
00xCanelo/CVE-2024-47533-PoC
CVE-2024-47533CRITICAL12 Aug 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open
GitHub PoC1
Esse script explora a vulnerabilidade CVE-2025-20124 — uma falha de Java Deserialization no Cisco ISE (Identity Services Engine) que permite Remote Code Execution (RCE).
CVE-2025-20124CRITICAL12 Aug 2025
Cisco Identity Services Engine Java Deserialization Vulnerability
53RISK
open
GitHub PoC1
PoC of CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware12 Aug 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
previouspage 215 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.