Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
75,652 exploits
VulnCheck XDB
infoleak
CVE-2025-25231HIGH12 Aug 2025
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to ga
61RISK
open
GitHub PoC8
CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.
CVE-2024-47533CRITICAL12 Aug 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open
GitHub PoC46
WinRAR 0day CVE-2025-8088 PoC RAR Archive
CVE-2025-8088HIGHunder attack12 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
Exploit-DB
Ghost CMS 5.42.1 - Path Traversal
CVE-2023-32235HIGHwebappsmultiple11 Aug 2025
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2
68RISK
open
GitHub PoC2
cve-2025-8088_detection
CVE-2025-8088HIGHunder attack11 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
Exploit-DB
Ghost CMS 5.59.1 - Arbitrary File Read
CVE-2023-40028MEDIUMwebappsmultiple11 Aug 2025
Arbitrary file read via symlinks in Ghost
45RISK
open
GitHub PoC3
CVE-2024-47533: Cobbler Authentication Bypass & Code Execution
CVE-2024-47533CRITICAL11 Aug 2025
Cobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
63RISK
open
GitHub PoC
These PoC python scripts test the Kemp LoadMaster for remote code execution.
CVE-2024-7591CRITICAL11 Aug 2025
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection
75RISK
open
Exploit-DB
Tigo Energy Cloud Connect Advanced (CCA) 4.0.1 - Command Injection
CVE-2025-7769HIGHremotemultiple11 Aug 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RISK
open
Exploit-DB
JetBrains TeamCity 2023.11.4 - Authentication Bypass
CVE-2024-27198CRITICALunder attackransomwarewebappsmultiple11 Aug 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
Exploit-DB
Belkin F9K1009 F9K1010 2.00.04/2.00.09 - Hard Coded Credentials
CVE-2025-8730CRITICALremotemultiple11 Aug 2025
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RISK
open
Exploit-DB
Microsoft Windows - Storage QoS Filter Driver Checker
CVE-2025-49730HIGHlocalwindows11 Aug 2025
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability
41RISK
open
Exploit-DB
VMware vSphere Client 8.0.3.0 - Reflected Cross-Site Scripting (XSS)
CVE-2025-41228MEDIUMwebappsmultiple11 Aug 2025
VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) Vulnerability
33RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack11 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Exploit-DB
ServiceNow Multiple Versions - Input Validation & Template Injection
CVE-2024-4879CRITICALunder attackwebappsmultiple11 Aug 2025
Jelly Template Injection Vulnerability in ServiceNow UI Macros
100RISK
open
GitHub PoC
alexander47777/CVE-2016-10033
CVE-2016-10033CRITICALunder attack11 Aug 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
Exploit-DB
projectworlds Online Admission System 1.0 - SQL Injection
CVE-2025-8471MEDIUMwebappsmultiple11 Aug 2025
projectworlds Online Admission System adminlogin.php sql injection
33RISK
open
Exploit-DB
atjiu pybbs 6.0.0 - Cross Site Scripting (XSS)
CVE-2025-8550MEDIUMwebappsmultiple11 Aug 2025
atjiu pybbs list cross site scripting
33RISK
open
Exploit-DB
Microsoft Edge Renderer Process (Mojo IPC) 134.0.6998.177 - Sandbox Escape
CVE-2025-2783HIGHunder attackwebappswindows11 Aug 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open
Exploit-DB
Microsoft SharePoint Server 2019 (16.0.10383.20020) - Remote Code Execution (RCE)
CVE-2025-53770CRITICALunder attackransomwareremotewindows11 Aug 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
Exploit-DB
Cisco ISE 3.0 - Remote Code Execution (RCE)
CVE-2025-20124CRITICALremotemultiple11 Aug 2025
Cisco Identity Services Engine Java Deserialization Vulnerability
53RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DB
Citrix NetScaler ADC/Gateway 14.1 - Memory Disclosure
CVE-2025-5777CRITICALunder attackransomwareremotemultiple11 Aug 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC
Update the old POC of CVE-2025-5777 Citrix NetScaler Memory leak
CVE-2025-5777CRITICALunder attackransomware11 Aug 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
Exploit-DB
Grav CMS 1.7.48 - Remote Code Execution (RCE)
CVE-2025-50286HIGHwebappsphp11 Aug 2025
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RISK
open
GitHub PoC4
Python exploit for vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-252311 Aug 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack11 Aug 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC
Bash POC script for RCE vulnerability in Apache 2.4.49
CVE-2021-41773HIGHunder attackransomware11 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Este script explora a vulnerabilidade CVE-2025-24813 em versões específicas do Apache Tomcat, permitindo execução remota de código (RCE) através de um vetor de desserialização Java e abuso do método HTTP PUT para gravação arbitrária de arquivos de sessão.
CVE-2025-24813CRITICALunder attack11 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Exploit-DB
Cisco ISE 3.0 - Authorization Bypass
CVE-2025-20125CRITICALremotemultiple11 Aug 2025
Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability
53RISK
open
previouspage 217 / 2,522next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.