Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,066cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
76,066 exploits
GitHub PoC2
The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads.
CVE-2024-8425CRITICAL19 Apr 2025
WooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
63RISK
open
GitHub PoC2
Simple Exploit for Dirty Pipe Vulnerability (CVE-2022-0847) This repository contains a simple proof of concept (PoC) for the Dirty Pipe vulnerability (CVE-2022-0847), which affects Linux kernel versions 5.8 to 5.16. This exploit demonstrates local privilege escalation by leveraging improper handling of pipe buffers in the kernel.
CVE-2022-0847HIGHunder attack19 Apr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware19 Apr 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38408CRITICAL19 Apr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC6
0xPThree/cve-2025-32433
CVE-2025-32433CRITICALunder attack19 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC7
CVE-2023-38408 SSH Vulnerability Scanner & PoC
CVE-2023-38408CRITICAL19 Apr 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC
Go-based exploit for CVE-2025-32433
CVE-2025-32433CRITICALunder attack19 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
JenmrR/Node.js-CVE-2024-39943
CVE-2024-39943CRITICAL19 Apr 2025
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth
60RISK
open
GitHub PoC16
The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC3
Exploitation module for CVE-2025-32433 (Erlang/OTP)
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC4
PoC - CVE-2025-24071 / CVE-2025-24054, NTMLv2 hash'leri alınabilen bir vulnerability
CVE-2025-24054MEDIUMunder attack18 Apr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC5
python script to find vulnerable targets of CVE-2025-32433
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC1
Erlang/OTP SSH 远程代码执行漏洞
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
Exploit-DB
KiviCare Clinic & Patient Management System (EHR) 3.6.4 - Unauthenticated SQL Injection
CVE-2024-11728HIGHwebappsphp18 Apr 2025
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection
61RISK
open
GitHub PoC3
Missing Authentication for Critical Function (CWE-306)-Exploit
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC3
Security research on Erlang/OTP SSH CVE-2025-32433.
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
Epivalent/CVE-2025-32433-detection
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC5
ekomsSavior/POC_CVE-2025-32433
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
FortiGate SSL-VPN CVE-2023-27997 Exploit PoC Script with ROP Chain
CVE-2023-27997CRITICALunder attackransomware18 Apr 2025
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
GitHub PoC142
CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
Exploit-DB
Langflow 1.3.0 - Remote Code Execution (RCE)
CVE-2025-3248CRITICALunder attackransomwareremotemultiple18 Apr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
local
CVE-2025-21756HIGH18 Apr 2025
vsock: Keep the binding until socket destruction
41RISK
open
Exploit-DB
Inventio Lite 4 - SQL Injection
CVE-2024-44541CRITICALwebappsphp18 Apr 2025
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action
48RISK
open
GitHub PoC1
This is for educational porpuses only. Please do not use agains unathorized systems.
CVE-2024-42327CRITICAL18 Apr 2025
SQL injection in user.get API
70RISK
open
Exploit-DB
Hunk Companion Plugin 1.9.0 - Unauthenticated Plugin Installation
CVE-2024-11972CRITICALwebappsmultiple18 Apr 2025
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RISK
open
GitHub PoC
PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)
CVE-2024-4577CRITICALunder attackransomware18 Apr 2025
Argument Injection in PHP-CGI
100RISK
open
Exploit-DB
Apache Commons Text 1.10.0 - Remote Code Execution
CVE-2022-42889webappsmultiple18 Apr 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-27997CRITICALunder attackransomware18 Apr 2025
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack18 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
Grand-Moomin/Vuln-Next.js-CVE-2025-29927
CVE-2025-29927CRITICAL18 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
previouspage 273 / 2,536next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.