Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,652cataloged exploits
34,545CVEs with public exploitation
24,695lab-tested
75,652 exploits
Exploit-DB
JetBrains TeamCity 2023.11.4 - Authentication Bypass
CVE-2024-27198CRITICALunder attackransomwarewebappsmultiple11 Aug 2025
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC10
Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.
CVE-2025-8088HIGHunder attack10 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
BiiTts/POC-IngressNightmare-CVE-2025-1974
CVE-2025-1974CRITICAL10 Aug 2025
ingress-nginx admission controller RCE escalation
85RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack10 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack10 Aug 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
GitHub PoC
kylew1004/cve-2017-5941-poc-docker-lab
CVE-2017-594110 Aug 2025
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
GitHub PoC
TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification
CVE-2024-25600CRITICAL09 Aug 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
A POC for CVE-2025-24893 written in python
CVE-2025-24893CRITICALunder attack09 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC4
POC exploit for CVE-2025-24893
CVE-2025-24893CRITICALunder attack09 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack09 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack09 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis
CVE-2014-6271CRITICALunder attack09 Aug 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC6
POC for CVE-2025-4404
CVE-2025-4404CRITICAL09 Aug 2025
Freeipa: idm: privilege escalation from host to domain admin in freeipa
48RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack09 Aug 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC2
Exploit demonstrating an authentication bypass vulnerability in the web interface of Belkin F9K1009 and F9K1010 routers.
CVE-2025-8730CRITICAL08 Aug 2025
Belkin F9K1009/F9K1010 Web Interface hard-coded credentials
48RISK
open
VulnCheck XDB
infoleak
CVE-2025-24354MEDIUM08 Aug 2025
imgproxy is vulnerable to SSRF against 0.0.0.0
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack08 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack08 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack08 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALunder attack08 Aug 2025
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC6
This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch
CVE-2025-24893CRITICALunder attack08 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC26
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
CVE-2025-32463CRITICALunder attack08 Aug 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC
CVE-2025-24893CRITICALunder attack08 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
POC
CVE-2025-24893CRITICALunder attack08 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions.
CVE-2018-7600CRITICALunder attackransomware08 Aug 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
一个由AI生成的漏洞验证应用
CVE-2022-22947CRITICALunder attack08 Aug 2025
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC1
PoC to inject a command via the DEVICE_PING endpoint
CVE-2025-7769HIGH07 Aug 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RISK
open
GitHub PoC
Scouserr/cve-2022-0847-poc-dockerimage
CVE-2022-0847HIGHunder attack07 Aug 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC5
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
CVE-2025-34152CRITICAL07 Aug 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISK
open
Metasploit400
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (time param)
CVE-2025-34152CRITICAL07 Aug 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISK
open
previouspage 218 / 2,522next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.