Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
75,902 exploits
GitHub PoC8
ekkoo-z/CVE-2019-18935-bypasswaf
CVE-2019-18935CRITICALunder attackransomware09 Jul 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack09 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack09 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
infoleak
CVE-2025-6554HIGHunder attack09 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
VulnCheck XDB
infoleak
CVE-2022-016909 Jul 2025
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
60RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware09 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware08 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
Exploit-DB
Discourse 3.2.x - Anonymous Cache Poisoning
CVE-2024-47773HIGHwebappsmultiple08 Jul 2025
Anonymous cache poisoning via XHR requests in Discourse
41RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack08 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware08 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
# cve-2025-32463 - Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-49704HIGHunder attackransomware08 Jul 2025
Microsoft SharePoint Remote Code Execution Vulnerability
88RISK
open
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-53770CRITICALunder attackransomware08 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-53771MEDIUM08 Jul 2025
Microsoft SharePoint Server Spoofing Vulnerability
50RISK
open
Exploit-DB
ScriptCase 9.12.006 (23) - Remote Command Execution (RCE)
CVE-2025-47228MEDIUMremotemultiple08 Jul 2025
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connecti
38RISK
open
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-49706MEDIUMunder attackransomware08 Jul 2025
Microsoft SharePoint Server Spoofing Vulnerability
100RISK
open
Exploit-DB
Sudo 1.9.17 Host Option - Elevation of Privilege
CVE-2025-32462LOWlocallinux08 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL08 Jul 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC
lowercasenumbers/CVE-2025-32463_sudo_chroot
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-9014CRITICAL08 Jul 2025
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISK
open
Exploit-DB
Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover
CVE-2024-50477CRITICALwebappsmultiple08 Jul 2025
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISK
open
GitHub PoC3
0xtensho/CVE-2025-49132-poc
CVE-2025-49132CRITICAL08 Jul 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
r0otk3r/CVE-2024-7954
CVE-2024-7954CRITICAL08 Jul 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
GitHub PoC52
Breaking git with a carriage return and cloning RCE
CVE-2025-48384HIGHunder attack08 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
previouspage 237 / 2,531next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.