Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,053cataloged exploits
34,675CVEs with public exploitation
24,695lab-tested
76,054 exploits
VulnCheck XDB
client-side
CVE-2023-43770MEDIUMunder attack20 Apr 2025
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISK
open
GitHub PoC2
nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327
CVE-2020-0796CRITICALunder attackransomware20 Apr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2021-44026CRITICALunder attack20 Apr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISK
open
GitHub PoC2
mouseos/cve-2019-2215_SH-M08
CVE-2019-2215HIGHunder attack20 Apr 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
GitHub PoC2
nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327
CVE-2019-7238CRITICALunder attack20 Apr 2025
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALunder attack20 Apr 2025
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-3102HIGH20 Apr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2020-35730MEDIUMunder attack20 Apr 2025
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack
75RISK
open
GitHub PoC
Bug Chain XSS (CVE-2020-35730 and CVE-2023-43770) to SQLi (CVE-2021-44026)
CVE-2023-43770MEDIUMunder attack20 Apr 2025
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with craft
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack20 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
client-side
CVE-2020-35730MEDIUMunder attack20 Apr 2025
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack
75RISK
open
GitHub PoC
JenmrR/Node.js-CVE-2024-39943
CVE-2024-39943CRITICAL19 Apr 2025
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth
60RISK
open
Exploit-DB
FoxCMS 1.2.5 - Remote Code Execution (RCE)
CVE-2025-29306CRITICALwebappsmultiple19 Apr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware19 Apr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38408CRITICAL19 Apr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC2
Simple Exploit for Dirty Pipe Vulnerability (CVE-2022-0847) This repository contains a simple proof of concept (PoC) for the Dirty Pipe vulnerability (CVE-2022-0847), which affects Linux kernel versions 5.8 to 5.16. This exploit demonstrates local privilege escalation by leveraging improper handling of pipe buffers in the kernel.
CVE-2022-0847HIGHunder attack19 Apr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack19 Apr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-8425CRITICAL19 Apr 2025
WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
63RISK
open
GitHub PoC
pruthuraut/CVE-2025-28121
CVE-2025-28121MEDIUM19 Apr 2025
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" p
33RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack19 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack19 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC2
The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads.
CVE-2024-8425CRITICAL19 Apr 2025
WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
63RISK
open
GitHub PoC1
cybermads/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware19 Apr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC6
0xPThree/cve-2025-32433
CVE-2025-32433CRITICALunder attack19 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
Go-based exploit for CVE-2025-32433
CVE-2025-32433CRITICALunder attack19 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC7
CVE-2023-38408 SSH Vulnerability Scanner & PoC
CVE-2023-38408CRITICAL19 Apr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC3
Exploitation module for CVE-2025-32433 (Erlang/OTP)
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
FortiGate SSL-VPN CVE-2023-27997 Exploit PoC Script with ROP Chain
CVE-2023-27997CRITICALunder attackransomware18 Apr 2025
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC4
PoC - CVE-2025-24071 / CVE-2025-24054, NTMLv2 hash'leri alınabilen bir vulnerability
CVE-2025-24054MEDIUMunder attack18 Apr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC16
The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
previouspage 272 / 2,536next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.