Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
76,107 exploits
VulnCheck XDB
client-side
CVE-2024-44308HIGHunder attack07 Apr 2025
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18
71RISK
open
VulnCheck XDB
client-side
CVE-2023-23397CRITICALunder attack07 Apr 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
CVE-2025-24813-POC JSP Web Shell Uploader
CVE-2025-24813CRITICALunder attack06 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
CVE-2024-9458MEDIUMwebappsphp06 Apr 2025
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RISK
open
GitHub PoC1
cybermads/CVE-2011-2523
CVE-2011-252306 Apr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
CVE-2024-8856CRITICALwebappsphp06 Apr 2025
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
GitHub PoC
VVeakee/CVE-2024-4367
CVE-2024-4367MEDIUM06 Apr 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
d0x-awrqxavc/-CVE-2024-10924
CVE-2024-10924CRITICAL06 Apr 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
A POC lab environment for CVE-2024-56145 CraftCMS RCE.
CVE-2024-56145CRITICALunder attack06 Apr 2025
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RISK
open
GitHub PoC
Koray123-debug/CVE-2024-34102
CVE-2024-34102CRITICALunder attack06 Apr 2025
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
Exploit-DB
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
CVE-2024-5910CRITICALunder attackwebappsmultiple06 Apr 2025
Expedition: Missing Authentication Leads to Admin Account Takeover
100RISK
open
GitHub PoC
vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL06 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL06 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL06 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
Exploit-DB
Watcharr 1.43.0 - Remote Code Execution (RCE)
CVE-2024-48827HIGHwebappsmultiple06 Apr 2025
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
41RISK
open
GitHub PoC33
Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation, and logging. Safe for red team demos, detection engineering, and educational use.
CVE-2025-2783HIGHunder attack06 Apr 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open
GitHub PoC8
Next.js Middleware Bypass Scanne
CVE-2025-29927CRITICAL06 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
CVE-2024-30269MEDIUMwebappsjava06 Apr 2025
DataEase has database configuration information exposure vulnerability
53RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL06 Apr 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC3
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
CVE-2025-2005CRITICAL06 Apr 2025
Front-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
53RISK
open
VulnCheck XDB
local
CVE-2024-0582HIGH05 Apr 2025
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open
Exploit-DB
IBM Security Verify Access 10.0.0 - Open Redirect during OAuth Flow
CVE-2024-35133MEDIUMwebappsmultiple05 Apr 2025
IBM Security Verify Access HTTP open redirect
33RISK
open
GitHub PoC4
simple exp for CVE-2025-24813
CVE-2025-24813CRITICALunder attack05 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC1
Apache Tomcat is vulnerable to a Path Equivalence / Path Traversal issue due to improper handling of ../ sequences in paths.
CVE-2025-24813CRITICALunder attack05 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM05 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC2
Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.
CVE-2011-252305 Apr 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL05 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack05 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack05 Apr 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Exploit-DB
Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)
CVE-2025-2294CRITICALwebappsmultiple05 Apr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
previouspage 284 / 2,537next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.