Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
GitHub PoC
POC for CVE-2025-24813 using Spring-Boot
CVE-2025-24813CRITICALunder attack20 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC1
minhluannguyen/CVE-2020-7247-reproducer
CVE-2020-7247CRITICALunder attack20 Mar 2025
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
GitHub PoC
PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)
CVE-2019-919320 Mar 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALunder attack20 Mar 2025
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALunder attack20 Mar 2025
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RISK
open
Metasploit600
ICTBroadcast Unauthenticated Remote Code Execution
CVE-2025-2611CRITICAL19 Mar 2025
ICTBroadcast <= 7.4 Unauthenticated Session Cookie RCE
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack19 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware19 Mar 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
Resources for teh Apache Tomcat CVE lab
CVE-2025-24813CRITICALunder attack19 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
CVE-2025-24071MEDIUM19 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
Apache Tomcat Vulnerability POC (CVE-2025-24813)
CVE-2025-24813CRITICALunder attack19 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC2
Alternativa CVE-2025-24071_PoC
CVE-2025-24071MEDIUM19 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
CVE-2018-7600.
CVE-2018-7600CRITICALunder attackransomware19 Mar 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC2
Koha CVE-2025-22954: SQL Injection in lateissues-export.pl
CVE-2025-22954CRITICAL19 Mar 2025
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi
53RISK
open
Exploit-DB
Extensive VC Addons for WPBakery page builder 1.9.0 - Remote Code Execution (RCE)
CVE-2023-0159webappsphp19 Mar 2025
Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
50RISK
open
VulnCheck XDB
infoleak
CVE-2025-24071MEDIUM19 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware19 Mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware19 Mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4587819 Mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RISK
open
GitHub PoC
CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware19 Mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
CVE-2024-56249CRITICAL18 Mar 2025
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC1
iOS/macOS library that exploits CVE-2023-41991 for signing iOS applications.
CVE-2023-41991MEDIUMunder attack18 Mar 2025
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal
63RISK
open
GitHub PoC7
Otsmane-Ahmed/cve-2025-29384-poc
CVE-2025-29384CRITICAL18 Mar 2025
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability
48RISK
open
VulnCheck XDB
infoleak
CVE-2025-1661CRITICAL18 Mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM18 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC2
CVE-2024-57040 is a security vulnerability found in certain TP-Link TL-WR845N router models. Specifically, it involves a "hardcoded" password for the router's root account. This means a default, unchanging password is built into the router's software.
CVE-2024-57040CRITICAL18 Mar 2025
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a
48RISK
open
GitHub PoC6
Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813
CVE-2025-24813CRITICALunder attack18 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL18 Mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISK
open
GitHub PoC1
Checkmarx/Checkmarx-CVE-2025-30066-Detection-Tool
CVE-2025-30066HIGHunder attack18 Mar 2025
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr
93RISK
open
GitHub PoC25
Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms
CVE-2025-24071MEDIUM18 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
previouspage 299 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.