Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
GitHub PoC1
MS17-010 (CVE-2017-0143) - Python3 Script
CVE-2017-0143HIGHunder attackransomware12 Mar 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC1
POC for CVE-2025-26240
CVE-2025-26240HIGH12 Mar 2025
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of t
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-0143HIGHunder attackransomware12 Mar 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware12 Mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC7
tinashelorenzi/CVE-2023-30258-magnus-billing-v7-exploit
CVE-2023-30258CRITICAL12 Mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
VulnCheck XDB
initial-access
CVE-2021-2564612 Mar 2025
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
Metasploit300
GLPI Inventory Plugin Unauthenticated Blind Boolean SQLi
CVE-2025-24799HIGH12 Mar 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL12 Mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
GitHub PoC
In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and CVE-2021-42013, which involve Path Traversal and Remote Code Execution (RCE).
CVE-2021-41773HIGHunder attackransomware11 Mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2017-11882 Preventer for .docx files
CVE-2017-11882HIGHunder attackransomware11 Mar 2025
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
CVE-2024-54383, https://www.cve.org/CVERecord?id=CVE-2024-54383
CVE-2024-54383CRITICAL11 Mar 2025
WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability
48RISK
open
GitHub PoC
CVE-2024-8289 https://www.cve.org/CVERecord?id=CVE-2024-8289, Vendor wcmp Product MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution
CVE-2024-8289CRITICAL11 Mar 2025
MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover
48RISK
open
GitHub PoC
Remote code execution running on w3 total cache cve 2013-2010
CVE-2013-201011 Mar 2025
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RISK
open
GitHub PoC
CVE-2024-10924 - Authentication Bypass in ReallySimpleSSL Wordpress Plugin
CVE-2024-10924CRITICAL11 Mar 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
KQL para deteccion de CVE-2025-21333 en Sentinel
CVE-2025-21333HIGHunder attack11 Mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
Metasploit600
Tomcat Partial PUT Java Deserialization
CVE-2025-24813CRITICALunder attack10 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack10 Mar 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC3
Ivanti Remote code execution
CVE-2025-0282CRITICALunder attackransomware10 Mar 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
GitHub PoC
Sp4ceDogy/NPE-CS-V-CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware10 Mar 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC15
Exploit for CVE-2024-0402 in Gitlab
CVE-2024-0402CRITICAL10 Mar 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
48RISK
open
GitHub PoC
Sornphut/CVE-2021-3156-Heap-Based-Buffer-Overflow-in-Sudo-Baron-Samedit-
CVE-2021-3156HIGHunder attack10 Mar 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
client-side
CVE-2017-118210 Mar 2025
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the sys
23RISK
open
VulnCheck XDB
local
CVE-2025-21333HIGHunder attack10 Mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware09 Mar 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL09 Mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-27636MEDIUM09 Mar 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
55RISK
open
GitHub PoC4
Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the SetupCompleted Java class.
CVE-2023-27350CRITICALunder attackransomware09 Mar 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
sk00l/CVE-2023-30258
CVE-2023-30258CRITICAL09 Mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
GitHub PoC
Zimbra CVE-2024-45519
CVE-2024-45519CRITICALunder attack08 Mar 2025
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
100RISK
open
GitHub PoC
elphon/CVE-2007-2447-Exploit
CVE-2007-244708 Mar 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
previouspage 302 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.