Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
GitHub PoC
liemkaka/CVE-2018-9206
CVE-2018-920627 Mar 2025
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
GitHub PoC
IngressNightmare (CVE-2025-1974)
CVE-2025-1974CRITICAL27 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC
A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted AdmissionReview request to simulate a potential exploit path from CVE-2025-1974 and checks for signs of misinterpreted annotations in controller logs.
CVE-2025-1974CRITICAL27 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2021-44228CRITICALunder attackransomware27 Mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
client-side
CVE-2025-30349HIGH27 Mar 2025
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take
53RISK
open
GitHub PoC1
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
CVE-2025-1974CRITICAL26 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC1
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
CVE-2024-12252CRITICAL26 Mar 2025
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
48RISK
open
GitHub PoC
PoC
CVE-2025-30216CRITICAL26 Mar 2025
CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
48RISK
open
GitHub PoC196
CVE-2025-30208-EXP
CVE-2025-30208MEDIUM26 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM26 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC2
EPICOR HCM Unauthenticated Blind SQL Injection CVE-2025-22953
CVE-2025-22953CRITICAL26 Mar 2025
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HC
48RISK
open
GitHub PoC2
New nuclei CVE
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Detection and exploitation scripts for CVE-2024-4956
CVE-2024-4956HIGH26 Mar 2025
Nexus Repository 3 - Path Traversal
61RISK
open
GitHub PoC97
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
CVE-2025-1974CRITICAL26 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC1
yugo-eliatrope/test-cve-2025-29927
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC8
Poc for Ingress RCE
CVE-2025-1974CRITICAL26 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC10
CVE-2025-30208-EXP 任意文件读取
CVE-2025-30208MEDIUM26 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC2
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
CVE-2025-1974CRITICAL26 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
Exploit-DB
NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
CVE-2024-0132CRITICALlocallinux26 Mar 2025
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RISK
open
GitHub PoC248
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
CVE-2025-1097HIGH26 Mar 2025
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISK
open
previouspage 294 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.