Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
75,902 exploits
GitHub PoC
hklabCR/CVE-2011-2523
CVE-2011-252306 Jul 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-55963MEDIUM06 Jul 2025
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
38RISK
open
GitHub PoC5
Proof of Concept for CVE-2025-32463 Local privilege escalation exploit targeting sudo -R on vulnerable Linux systems. For educational and authorized security testing only.
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC2
CitrixBleed-2 Checker & Poc automatic exploit and check token.
CVE-2025-5777CRITICALunder attackransomware06 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC9
A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
Chocapikk/CVE-2025-32463-lab
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC2
CVE-2024-55963, allows unauthenticated remote code execution on Appsmith Enterprise platform due to a misconfigured PostgreSQL database included by default
CVE-2024-55963MEDIUM06 Jul 2025
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
38RISK
open
GitHub PoC
Citrix Bleed 2 PoC Scanner (CVE-2025-5777)
CVE-2025-5777CRITICALunder attackransomware06 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC3
ibrahmsql/CVE-2023-45131
CVE-2023-45131HIGH06 Jul 2025
Unauthenticated access to new private chat messages in Discourse
41RISK
open
GitHub PoC2
NoobCat2000/CVE-2022-37969
CVE-2022-37969HIGHunder attack06 Jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2021-2564606 Jul 2025
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware06 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL06 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware06 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC1
An analysis and demonstration of the unauthenticated SQL Injection vulnerability (CVE-2022-3141) in ACS EDU 3rd Gen.
CVE-2022-314106 Jul 2025
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISK
open
GitHub PoC216
PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"
CVE-2025-32023HIGH06 Jul 2025
Redis allows out of bounds writes in hyperloglog commands leading to RCE
41RISK
open
GitHub PoC
Royall-Researchers/CVE-2024-9264
CVE-2024-9264CRITICAL05 Jul 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC
CitrixBleed2 poc
CVE-2025-5777CRITICALunder attackransomware05 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC
Grafana RCE
CVE-2024-9264CRITICAL05 Jul 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC2
ibrahmsql/discourse-CVE-2021-41163
CVE-2021-41163CRITICAL05 Jul 2025
RCE via malicious SNS subscription payload
53RISK
open
GitHub PoC3
ibrahmsql/CVE-2021-41163
CVE-2021-41163CRITICAL05 Jul 2025
RCE via malicious SNS subscription payload
53RISK
open
GitHub PoC
Papercut Vulnerability, Affected Versions are PaperCut MF or NG version 8.0 or later (excluding patched versions) on all OS platforms.
CVE-2023-27350CRITICALunder attackransomware05 Jul 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALunder attack05 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC3
cve-2025-32462' demo
CVE-2025-32462LOW05 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC3
Memory disclosure vulnerability in Citrix NetScaler ADC and Gateway when configured as a Gateway (VPN virtual server, ICA proxy, CVPN, RDP Proxy).
CVE-2025-5777CRITICALunder attackransomware05 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware05 Jul 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC1
Mezzanine CMS 6.1.0 XSS (CVE-2025-50481)
CVE-2025-50481MEDIUM05 Jul 2025
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers
33RISK
open
GitHub PoC
Royall-Researchers/CVE-2025-24071
CVE-2025-24071MEDIUM05 Jul 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
previouspage 239 / 2,531next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.