Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
75,589 exploits
GitHub PoC108
fearsoff-org/CVE-2025-49113
CVE-2025-49113CRITICALunder attack04 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
client-side
CVE-2025-4123HIGH04 Jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
GitHub PoC
Superliverbun/cve-2021-3156-
CVE-2021-3156HIGHunder attack04 Jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
An exploit automation script that builds upon the work of Voidzone security.
CVE-2022-44268MEDIUM04 Jun 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH03 Jun 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM03 Jun 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
client-side
CVE-2025-4123HIGH03 Jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL03 Jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC
imbas007/CVE-2025-4123-template
CVE-2025-4123HIGH03 Jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
GitHub PoC
Authenticated Remote Command Execution – pfSense <= 2.1.3
CVE-2014-468803 Jun 2025
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RISK
open
GitHub PoC3
pgAdmin Proof of Concept
CVE-2025-2945CRITICAL03 Jun 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISK
open
GitHub PoC1
A XZ backdoor vulnerability explained in details
CVE-2024-3094CRITICAL03 Jun 2025
Xz: malicious code in distributed source
70RISK
open
GitHub PoC2
r007sec/CVE-2024-53677
CVE-2024-53677CRITICAL03 Jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC5
Detection for CVE-2025-49113
CVE-2025-49113CRITICALunder attack03 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
For CTF use only (the CVE-2019-7214 also resolves the host from /etc/hosts)
CVE-2019-721403 Jun 2025
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RISK
open
GitHub PoC3
A reflected cross-site scripting (XSS) vulnerability exists in MailEnable Webmail due to improper user input sanitization in the failure.aspx. This allows a remote attacker to inject arbitrary JavaScript code via a crafted URL, which is then reflected in the server's response and executed in the context of the user's browser session.
CVE-2025-44148CRITICAL02 Jun 2025
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via
75RISK
open
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALunder attack02 Jun 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
VulnCheck XDB
infoleak
CVE-2018-999502 Jun 2025
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC
MS08-067 | CVE-2008-4250
CVE-2008-4250CRITICALunder attack02 Jun 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
Metasploit600
Roundcube Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALunder attack02 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-25690CRITICAL01 Jun 2025
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
GitHub PoC6
CTY-Research-1/CVE-2025-32432-PoC
CVE-2025-32432CRITICALunder attack01 Jun 2025
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC2
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
CVE-2023-25690CRITICAL01 Jun 2025
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
GitHub PoC
Vbullettin RCE - CVE-2025-48827
CVE-2025-48827CRITICAL31 May 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISK
open
GitHub PoC3
A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.
CVE-2024-9264CRITICAL31 May 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
VulnCheck XDB
client-side
CVE-2025-30397HIGHunder attack31 May 2025
Scripting Engine Memory Corruption Vulnerability
76RISK
open
VulnCheck XDB
infoleak
CVE-2025-5287HIGH31 May 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RISK
open
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL31 May 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISK
open
GitHub PoC1
fatkz/CVE-2025-27590
CVE-2025-27590CRITICAL31 May 2025
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr
53RISK
open
GitHub PoC1
This Python script exploits CVE-2025-3248 to execute arbitrary commands or spawn a reverse shell on a vulnerable system. Authentication is required to use this exploit.
CVE-2025-3248CRITICALunder attackransomware31 May 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
previouspage 252 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.