Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
76,008 exploits
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware27 Apr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack27 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack27 Apr 2025
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-8291HIGHunder attack27 Apr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288927 Apr 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL27 Apr 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2017-8291HIGHunder attack27 Apr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISK
open
GitHub PoC
Updated exploit script for the CVE-2021-43798
CVE-2021-43798HIGHunder attack27 Apr 2025
Grafana path traversal
100RISK
open
GitHub PoC12
Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
CVE-2025-31324CRITICALunder attackransomware27 Apr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack27 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMunder attack27 Apr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC24
CVE-2025-31324, SAP Exploit
CVE-2025-31324CRITICALunder attackransomware27 Apr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-15133HIGHunder attack27 Apr 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31324CRITICALunder attackransomware27 Apr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
GitHub PoC2
CVE-2022-3552 RCE with detailed exploitation steps
CVE-2022-3552HIGH27 Apr 2025
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RISK
open
GitHub PoC
airtiels 5650 CVE-2015-2797 PoC
CVE-2015-279727 Apr 2025
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RISK
open
GitHub PoC1
yeahhbean/Laravel-CVE-2018-15133
CVE-2018-15133HIGHunder attack27 Apr 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC
romanedutov/CVE-2025-2294
CVE-2025-2294CRITICAL26 Apr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC1
chhhd/CVE-2025-1974
CVE-2025-1974CRITICAL26 Apr 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC10
CraftCMS RCE Checker (CVE-2025-32432)
CVE-2025-32432CRITICALunder attack26 Apr 2025
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC2
CVE-2021-42287/CVE-2021-42278/OTHER Scanner & Exploiter.
CVE-2021-42287HIGHunder attackransomware26 Apr 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL26 Apr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC
ChoDeokCheol/CVE-2023-39361
CVE-2023-39361CRITICAL26 Apr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-1389HIGHunder attack26 Apr 2025
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-39361CRITICAL26 Apr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALunder attack26 Apr 2025
Craft CMS Allows Remote Code Execution
100RISK
open
VulnCheck XDB
client-side
CVE-2021-41773HIGHunder attackransomware26 Apr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL25 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL25 Apr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
GitHub PoC4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
CVE-2025-31324CRITICALunder attackransomware25 Apr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
previouspage 268 / 2,534next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.