Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
75,902 exploits
GitHub PoC
MandipJoshi/CVE-2021-3560
CVE-2021-3560HIGHunder attack13 May 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL13 May 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC1
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL13 May 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC2
CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.
CVE-2025-3248CRITICALunder attackransomware13 May 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
Exploit-DB
TP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer Overflow
CVE-2024-11237HIGHlocalmultiple13 May 2025
TP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflow
41RISK
open
VulnCheck XDB
local
CVE-2025-24085CRITICALunder attack13 May 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RISK
open
Exploit-DB
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
CVE-2025-3605CRITICALwebappsmultiple13 May 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISK
open
GitHub PoC3
rebelle3/cve-2017-7117
CVE-2017-711712 May 2025
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RISK
open
GitHub PoC
shishirpandey18/CVE-2021-3156
CVE-2021-3156HIGHunder attack12 May 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack12 May 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
CVE-2025-4603CRITICAL12 May 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 May 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC55
WHW0x455/CVE-2023-41992
CVE-2023-41992HIGHunder attack12 May 2025
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macO
71RISK
open
GitHub PoC
使用PowsrShell掃描CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware12 May 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
laishouchao/Apache-RocketMQ-RCE-CVE-2023-37582-poc
CVE-2023-37582CRITICAL12 May 2025
Apache RocketMQ: Possible remote code execution when using the update configuration function
85RISK
open
GitHub PoC1
fatkz/CVE-2025-24813
CVE-2025-24813CRITICALunder attack11 May 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC1
PolarisXSec/CVE-2024-21413
CVE-2024-21413CRITICALunder attack11 May 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Windows & linux support
CVE-2023-42793CRITICALunder attackransomware11 May 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware11 May 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
client-side
CVE-2025-0411HIGHunder attack11 May 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack11 May 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack11 May 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
CVE-2025-0411 7-Zip Mark-of-the-Web Bypass
CVE-2025-0411HIGHunder attack11 May 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open
GitHub PoC1
Apache CXF SSRF CVE-2024-28752
CVE-2024-28752CRITICAL10 May 2025
Apache CXF SSRF Vulnerability using the Aegis databinding
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack10 May 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL10 May 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
GitHub PoC2
WordPress PDF 2 Post Plugin <= 2.4.0 is vulnerable to Remote Code Execution (RCE) +Subscriber
CVE-2025-32583CRITICAL10 May 2025
WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
53RISK
open
GitHub PoC
congdong007/CVE-2025-29306_poc
CVE-2025-29306CRITICAL10 May 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
GitHub PoC3
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
CVE-2025-4403CRITICAL10 May 2025
Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function
48RISK
open
GitHub PoC
PoC for CVE-2017-5487 - WordPress User Enumeration via REST
CVE-2017-548710 May 2025
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
previouspage 261 / 2,531next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.