Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,006cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
75,589 exploits
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware06 Jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH06 Jun 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
GitHub PoC
🚨 Exploit CVE-2025-55182 to demonstrate RCE in React Server Functions, highlighting risks from insecure prototype references in Next.js applications.
CVE-2025-55182CRITICALunder attackransomware06 Jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-14871CRITICALunder attack06 Jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM06 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC92
Proof of Concept demonstrating Remote Code Execution through insecure deserialization in Roundcube (CVE-2025-49113).
CVE-2025-49113CRITICALunder attack06 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
POC
CVE-2025-30208MEDIUM06 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC2
CVE-2025-49113 exploit
CVE-2025-49113CRITICALunder attack06 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-46604HIGH05 Jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISK
open
Exploit-DB
Microsoft Windows Server 2025 JScript Engine - Remote Code Execution (RCE)
CVE-2025-30397HIGHunder attackremotewindows05 Jun 2025
Scripting Engine Memory Corruption Vulnerability
76RISK
open
Exploit-DB
Apache Tomcat 10.1.39 - Denial of Service (DoS)
CVE-2025-31650HIGHremotemultiple05 Jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISK
open
GitHub PoC3
rasool13x/exploit-CVE-2025-49113
CVE-2025-49113CRITICALunder attack05 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack05 Jun 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
Exploit-DB
CloudClassroom PHP Project 1.0 - SQL Injection
CVE-2025-45542HIGHwebappsphp05 Jun 2025
SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack05 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-32756CRITICALunder attack05 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open
GitHub PoC
PoC for CVE-2024-42049
CVE-2024-42049CRITICAL05 Jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RISK
open
GitHub PoC198
Proof of Concept for CVE-2025-32756 - A critical stack-based buffer overflow vulnerability affecting multiple Fortinet products.
CVE-2025-32756CRITICALunder attack05 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open
Exploit-DB
macOS LaunchDaemon iOS 17.2 - Privilege Escalation
CVE-2025-24085CRITICALunder attacklocalmacos05 Jun 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RISK
open
GitHub PoC1
CyberQuestor-infosec/CVE-2022-46604-Responsive-File-Manager
CVE-2022-46604HIGH05 Jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISK
open
GitHub PoC1
Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.
CVE-2021-4034HIGHunder attack05 Jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
Exploit-DB
Grandstream GSD3710 1.0.11.13 - Stack Overflow
CVE-2022-2025CRITICALremotemultiple05 Jun 2025
Grandstream GSD3710 Stack-based Buffer Overflow
48RISK
open
GitHub PoC
An exploit automation script that builds upon the work of Voidzone security.
CVE-2022-44268MEDIUM04 Jun 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC108
fearsoff-org/CVE-2025-49113
CVE-2025-49113CRITICALunder attack04 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC3
CVE-2025-49113 - Roundcube <= 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALunder attack04 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
A repository used for Hackthebox ServMon Machine
CVE-2019-20085HIGHunder attack04 Jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
GitHub PoC32
CVE-2025-4123 - Grafana Tool
CVE-2025-4123HIGH04 Jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
GitHub PoC
Authenticated Remote Command Execution - Webmin <= 1.910
CVE-2019-1284004 Jun 2025
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open
GitHub PoC
MantisToboggan-git/CVE-2025-4632-POC
CVE-2025-4632CRITICALunder attack04 Jun 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
98RISK
open
GitHub PoC
Superliverbun/cve-2021-3156-
CVE-2021-3156HIGHunder attack04 Jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
previouspage 251 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.