Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
76,107 exploits
Exploit-DB
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
CVE-2024-7815MEDIUMwebappsphp10 Apr 2025
CodeAstro Online Railway Reservation System Update Employee Page admin-update-employee.php cross site scripting
33RISK
open
Exploit-DB
PandoraFMS 7.0NG.772 - SQL Injection
CVE-2023-44088MEDIUMwebappsphp10 Apr 2025
SQL Injection in Visual Console
33RISK
open
VulnCheck XDB
initial-access
CVE-2022-37932HIGH10 Apr 2025
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S
56RISK
open
Exploit-DB
Cisco Smart Software Manager On-Prem 8-202206 - Account Takeover
CVE-2024-20419CRITICALwebappsmultiple10 Apr 2025
A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
85RISK
open
Exploit-DB
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
CVE-2024-35540HIGHwebappsphp10 Apr 2025
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or
41RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-22457CRITICALunder attackransomware10 Apr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISK
open
GitHub PoC
OD&H's scanner for CVE-2024-25600 vulnerability in the Bricks Builder WordPress plugin. For use in Try Hack Me (THM) environments.
CVE-2024-25600CRITICAL09 Apr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
Exploit-DB
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
CVE-2024-27348CRITICALunder attackwebappsjava09 Apr 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-22457CRITICALunder attackransomware09 Apr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISK
open
Exploit-DB
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
CVE-2024-38944CRITICALwebappsmultiple09 Apr 2025
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the
48RISK
open
Exploit-DB
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
CVE-2024-39143MEDIUMwebappsphp09 Apr 2025
A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to crea
33RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL09 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.
CVE-2025-29927CRITICAL09 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
Exploit-DB
Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
CVE-2024-24409HIGHwebappsmultiple09 Apr 2025
Privilege Escalation
41RISK
open
Metasploit600
BentoML's runner server RCE
CVE-2025-32375CRITICAL09 Apr 2025
Insecure Deserialization leads to RCE in BentoML's runner server
75RISK
open
Metasploit600
Langflow AI RCE
CVE-2025-3248CRITICALunder attackransomware09 Apr 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
Exploit-DB
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
CVE-2024-6244HIGHwebappsphp09 Apr 2025
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RISK
open
Exploit-DB
Artica Proxy 4.50 - Remote Code Execution (RCE)
CVE-2024-2054CRITICALwebappsphp09 Apr 2025
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RISK
open
GitHub PoC2
a lightweight JavaScript snippet showcasing how unauthorized password changes can be triggered on vulnerable Fortinet FortiSwitch GUI endpoints.
CVE-2024-48887CRITICAL09 Apr 2025
A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c
53RISK
open
GitHub PoC1
A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).
CVE-2025-24813CRITICALunder attack09 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC73
PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA Gateways
CVE-2025-22457CRITICALunder attackransomware09 Apr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISK
open
Exploit-DB
ChurchCRM 5.9.1 - SQL Injection
CVE-2024-39304HIGHwebappsphp09 Apr 2025
ChurchCRM SQL Injection Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL09 Apr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
Exploit-DBVexDay Proof
DocsGPT 0.12.0 - Remote Code Execution
CVE-2025-0868CRITICALwebappspython09 Apr 2025
Remote Code Execution in DocsGPT
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack09 Apr 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
CVE-2019-11358webappsmultiple08 Apr 2025
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RISK
open
VulnCheck XDB
local
CVE-2025-26633HIGHunder attackransomware08 Apr 2025
Microsoft Management Console Security Feature Bypass Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack08 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-282508 Apr 2025
35RISK
open
GitHub PoC1
0xnxt1me/CVE-2025-29927
CVE-2025-29927CRITICAL08 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
previouspage 282 / 2,537next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.