Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
75,902 exploits
VulnCheck XDB
local
CVE-2025-21756HIGH26 Jun 2025
vsock: Keep the binding until socket destruction
41RISK
open
GitHub PoC7
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
CVE-2025-4334CRITICAL26 Jun 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISK
open
GitHub PoC4
Remote Code execution in CentOS web panel
CVE-2025-48703CRITICALunder attack26 Jun 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
Exploit-DB
freeSSHd 1.0.9 - Denial of Service (DoS)
CVE-2024-0723MEDIUMremotewindows26 Jun 2025
freeSSHd denial of service
33RISK
open
Exploit-DB
McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
CVE-2022-1257MEDIUMremotemultiple26 Jun 2025
Improper Verification of Cryptographic Signature by McAfee Agent
33RISK
open
VulnCheck XDB
initial-access
CVE-2025-48703CRITICALunder attack26 Jun 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
Exploit-DB
Microsoft Excel 2024 Use after free - Remote Code Execution (RCE)
CVE-2025-47165HIGHremotewindows26 Jun 2025
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
CVE-2025-49132CRITICALwebappsmultiple26 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
Exploit-DB
PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
CVE-2025-5640MEDIUMremotemultiple26 Jun 2025
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISK
open
Exploit-DB
Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE)
CVE-2019-9978MEDIUMunder attackwebappsmultiple26 Jun 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
Exploit-DB
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
CVE-2024-57708MEDIUMremotelinux26 Jun 2025
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISK
open
GitHub PoC5
Script para determinar si Citrix es vulnerable al CVE-2025-6543
CVE-2025-6543CRITICALunder attack26 Jun 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
78RISK
open
Exploit-DB
Sitecore 10.4 - Remote Code Execution (RCE)
CVE-2025-27218MEDIUMwebappsmultiple26 Jun 2025
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RISK
open
Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
CVE-2024-51977MEDIUM25 Jun 2025
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RISK
open
Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
CVE-2024-51978CRITICAL25 Jun 2025
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RISK
open
GitHub PoC
Poc - CVE-2025-49132
CVE-2025-49132CRITICAL25 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones para su uso en entornos controlados.
CVE-2016-5195HIGHunder attack25 Jun 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2024-43917CRITICAL25 Jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open
GitHub PoC
luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware25 Jun 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
VulnCheck XDB
local
CVE-2019-573625 Jun 2025
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware25 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1273CRITICALunder attackransomware25 Jun 2025
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM25 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVE-2025-3248CRITICALunder attackransomware25 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
C-based PoC for CVE-2019-5736
CVE-2019-573625 Jun 2025
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.9.2 CVE-2025-47577 PoC
CVE-2025-47577CRITICAL25 Jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RISK
open
VulnCheck XDB
infoleak
CVE-2025-49132CRITICAL25 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
infoleak
CVE-2024-10924CRITICAL25 Jun 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
hdgokani/CVE-2018-1273
CVE-2018-1273CRITICALunder attackransomware25 Jun 2025
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
GitHub PoC
Batch RCE scanner for vulnerable vBulletin instances using replaceAdTemplate exploit.
CVE-2025-48828CRITICAL25 Jun 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISK
open
previouspage 245 / 2,531next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.