Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
76,107 exploits
Exploit-DB
Xinet Elegant 6 Asset Lib Web UI 6.1.655 - SQL Injection
CVE-2019-19245webappsmultiple14 Apr 2025
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[use
23RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH14 Apr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
GitHub PoC
AsierEgana/cve-2021-4034
CVE-2021-4034HIGHunder attack14 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware14 Apr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution,
CVE-2021-42362HIGH14 Apr 2025
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH14 Apr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
GitHub PoC
nagorealbisu/CVE-2021-4034
CVE-2021-4034HIGHunder attack13 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
ikerSandoval003/CVE-2021-4034
CVE-2021-4034HIGHunder attack13 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.
CVE-2018-1676313 Apr 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
Este repositorio muestra cómo explotar la vulnerabilidad CVE-2021-4034.
CVE-2021-4034HIGHunder attack13 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
POC CVE-2025-29927
CVE-2025-29927CRITICAL13 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Exploit de la vulneravilidad CVE-2021-4034
CVE-2021-4034HIGHunder attack13 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack13 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack13 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL13 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack13 Apr 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack13 Apr 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
spyata123/CVE-2023-3128
CVE-2023-3128CRITICAL13 Apr 2025
Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique a
48RISK
open
GitHub PoC1
PHP CGI CVE-2024-4577 PoC
CVE-2024-4577CRITICALunder attackransomware12 Apr 2025
Argument Injection in PHP-CGI
100RISK
open
Metasploit600
Web-Check Screenshot API Command Injection RCE
CVE-2025-32778CRITICAL12 Apr 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISK
open
GitHub PoC3
A Python proof-of-concept exploit for CVE-2025-24813 - Unauthenticated RCE in Apache Tomcat (v9.0.0-9.0.98/10.1.0-10.1.34/11.0.0-11.0.2) via malicious Java object deserialization. Includes safe detection mode and custom payload support.
CVE-2025-24813CRITICALunder attack12 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC5
CVE-2025-24813-Scanner is a Python-based vulnerability scanner that detects Apache Tomcat servers vulnerable to CVE-2025-24813, an arbitrary file upload vulnerability leading to remote code execution (RCE) via insecure PUT method handling and jsessionid exploitation.
CVE-2025-24813CRITICALunder attack12 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
PoC of CVE-2023-1177 vulnerability in MLflow (Reproduce)
CVE-2023-1177CRITICAL12 Apr 2025
Path Traversal: '\..\filename' in mlflow/mlflow
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack12 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH12 Apr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH12 Apr 2025
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 Apr 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack12 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
ReFlex Gallery (WordPress plugin) =< 3.1.3 CVE-2015-4133 PoC
CVE-2015-413312 Apr 2025
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack12 Apr 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
previouspage 279 / 2,537next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.