Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
76,008 exploits
VulnCheck XDB
initial-access
CVE-2024-23897CRITICALunder attackransomware04 Apr 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL04 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-38163CRITICALunder attack04 Apr 2025
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL04 Apr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
Exploit-DB
Microchip TimeProvider 4100 (Configuration modules) 2.4.6 - OS Command Injection
CVE-2024-9054HIGHremotehardware04 Apr 2025
Remote code Execution inTimeProvider® 4100
46RISK
open
Metasploit600
BentoML RCE
CVE-2025-27520CRITICAL04 Apr 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-282504 Apr 2025
35RISK
open
GitHub PoC12
PoC
CVE-2025-30065CRITICAL04 Apr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISK
open
GitHub PoC
CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability
CVE-2021-38163CRITICALunder attack04 Apr 2025
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RISK
open
GitHub PoC7
This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It abuses the getDefaultValue() mechanism to instantiate arbitrary record types during parsing, enabling code execution when untrusted data is processed without proper controls.
CVE-2025-30065CRITICAL04 Apr 2025
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISK
open
GitHub PoC
WordPress RomethemeKit For Elementor Plugin <= 1.5.4 is vulnerable to Remote Code Execution (RCE)
CVE-2025-30911CRITICAL04 Apr 2025
WordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability
48RISK
open
GitHub PoC
sn1p3rt3s7/NextJS_CVE-2025-29927
CVE-2025-29927CRITICAL04 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Jenkins CLI arbitrary read (CVE-2024-23897 applies to versions below 2.442 and LTS 2.426.3)
CVE-2024-23897CRITICALunder attackransomware04 Apr 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
Exploit-DB
Angular-Base64-Upload Library 0.1.20 - Remote Code Execution (RCE)
CVE-2024-42640CRITICALremotemultiple04 Apr 2025
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo
75RISK
open
Exploit-DB
Microchip TimeProvider 4100 Grandmaster (Banner Config Modules) 2.4.6 - Stored Cross-Site Scripting (XSS)
CVE-2024-43687HIGHremotehardware04 Apr 2025
XSS vulnerability in bannerconfig endpoint in TimeProvider 4100
41RISK
open
GitHub PoC1
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server.
CVE-2025-31131HIGH04 Apr 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RISK
open
GitHub PoC
all3njk/NextJS_CVE-2025-29927
CVE-2025-29927CRITICAL04 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Subrion File Upload Bypass to RCE and Custom File Upload (Authenticated) POC
CVE-2018-1942204 Apr 2025
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RISK
open
GitHub PoC
PoC for CVE-2024-25600
CVE-2024-25600CRITICAL04 Apr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
Exploit-DB
Vite 6.2.2 - Arbitrary File Read
CVE-2025-30208MEDIUMremotemultiple03 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
Exploit-DB
ABB Cylon Aspect 3.07.01 - Hard-coded Default Credentials
CVE-2024-4007HIGHwebappsphp03 Apr 2025
Hard coded default credential contained in install package
41RISK
open
GitHub PoC7
CVE-2025-30208 - Vite Arbitrary File Read PoC
CVE-2025-30208MEDIUM03 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)
CVE-2025-29927CRITICAL03 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
Exploit-DB
Webmin Usermin 2.100 - Username Enumeration
CVE-2024-44762MEDIUMwebappsperl03 Apr 2025
A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
48RISK
open
Metasploit600
Gladinet CentreStack/Triofox ASP.NET ViewState Deserialization
CVE-2025-30406CRITICALunder attack03 Apr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
GitHub PoC
Mongo Vulnub Lab...Try to Hack IT.....!
CVE-2024-53900CRITICAL03 Apr 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RISK
open
Metasploit500
Ivanti Connect Secure Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
CVE-2025-22457CRITICALunder attackransomware03 Apr 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7
100RISK
open
Metasploit600
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
CVE-2025-2945CRITICAL03 Apr 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISK
open
Exploit-DB
Microsoft Office 2019 MSO Build 1808 - NTLMv2 Hash Disclosure
CVE-2024-38200MEDIUMremotewindows03 Apr 2025
Microsoft Office Spoofing Vulnerability
38RISK
open
Metasploit300
Gladinet CentreStack/Triofox Path Traversal
CVE-2025-11371HIGHunder attack03 Apr 2025
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RISK
open
previouspage 283 / 2,534next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.