Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
76,008 exploits
VulnCheck XDB
infoleak
CVE-2025-32433CRITICALunder attack25 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
WonderCMS v3.4.2 NSE Discovery Script
CVE-2023-41425MEDIUM25 Apr 2025
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RISK
open
GitHub PoC2
Next.js middleware bypass exploit
CVE-2025-29927CRITICAL25 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC5
Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets, executes commands, and reports vulnerable hosts.
CVE-2025-29306CRITICAL25 Apr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware25 Apr 2025
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL25 Apr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
GitHub PoC4
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
CVE-2025-31324CRITICALunder attackransomware25 Apr 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack25 Apr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC
A PoC of CVE-2016-2098 I made for PentesterLab
CVE-2016-209825 Apr 2025
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISK
open
GitHub PoC
A PoC of CVE-2016-10033 I made for PentesterLab
CVE-2016-10033CRITICALunder attack25 Apr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC
CyprianAtsyor/CVE-2024-24919-Incident-Report.md
CVE-2024-24919HIGHunder attackransomware25 Apr 2025
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL25 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
A PoC of CVE-2018-0114 I made for PentesterLab
CVE-2018-011425 Apr 2025
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC
Python Proof of Concept for CVE-2023-1545 (SQL Injection for Teampass versions prior to 3.0.0.23).
CVE-2023-1545HIGH25 Apr 2025
SQL Injection in nilsteampassnet/teampass
41RISK
open
GitHub PoC
K4Der11000/k4_cve-2023-41064
CVE-2023-41064HIGHunder attack25 Apr 2025
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1
76RISK
open
GitHub PoC
A PoC of CVE-2019-5420 I made for PentesterLab
CVE-2019-542025 Apr 2025
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open
GitHub PoC3
CVE-2023-25157 exp
CVE-2023-25157CRITICAL24 Apr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
GitHub PoC12
Exploit for CVE-2025-30406
CVE-2025-30406CRITICALunder attack24 Apr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware24 Apr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM24 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
Jasurbek-Masimov/CVE-2018-15745
CVE-2018-1574524 Apr 2025
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-282524 Apr 2025
35RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALunder attack24 Apr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
GitHub PoC3
Analysis of the Reproduction of CVE-2025-30208 Series Vulnerabilities
CVE-2025-30208MEDIUM24 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC1
tar-fs file write/overwrite vulnerability
CVE-2024-12905HIGH24 Apr 2025
An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted
41RISK
open
GitHub PoC
Commvault CVE-2025-34028 endpoint scanner using Nmap NSE. For ethical testing and configuration validation.
CVE-2025-34028CRITICALunder attack24 Apr 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
GitHub PoC
unzip-stream file write/overwrite vulnerability
CVE-2024-42471HIGH24 Apr 2025
Arbitrary File Write via artifact extraction in actions/artifact
41RISK
open
previouspage 269 / 2,534next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.