Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
VulnCheck XDB
initial-access
CVE-2024-46507HIGH04 Mar 2025
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti befor
56RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHunder attack04 Mar 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2020-35391CRITICAL02 Mar 2025
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open
GitHub PoC
Project on CVE-2022-30190 exploitation and mitigation strategies
CVE-2022-30190HIGHunder attackransomware02 Mar 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
Metasploit300
Xorcom CompletePBX Authenticated File Disclosure via Backup Download
CVE-2025-2292MEDIUM02 Mar 2025
Xorcom CompletePBX <= 5.2.35 Authenticated File Disclosure
28RISK
open
Metasploit300
Xorcom CompletePBX Arbitrary File Read and Deletion via systemDataFileName
CVE-2025-30005HIGH02 Mar 2025
Xorcom CompletePBX <= 5.2.35 Authenticated Path Traversal & File Deletion
36RISK
open
Metasploit600
Xorcom CompletePBX Authenticated Command Injection via Task Scheduler
CVE-2025-30004HIGH02 Mar 2025
Xorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection
36RISK
open
GitHub PoC3
Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.
CVE-2020-35391CRITICAL02 Mar 2025
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open
GitHub PoC
GazettEl/CVE-2020-17519
CVE-2020-17519CRITICALunder attack02 Mar 2025
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC129
Deterministic kernel exploit based on CVE-2023-32434.
CVE-2023-32434HIGHunder attack01 Mar 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISK
open
VulnCheck XDB
local
CVE-2023-32434HIGHunder attack01 Mar 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISK
open
VulnCheck XDB
initial-access
CVE-2019-1003030CRITICALunder attack01 Mar 2025
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware01 Mar 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC1
overgrowncarrot1/CVE-2019-1003030
CVE-2019-1003030CRITICALunder attack01 Mar 2025
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open
GitHub PoC
CVE-2019-18935: Remote Code Execution
CVE-2019-18935CRITICALunder attackransomware01 Mar 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
CVE-2023-1545-POC with python
CVE-2023-1545HIGH01 Mar 2025
SQL Injection in nilsteampassnet/teampass
41RISK
open
GitHub PoC4
Mautic < 5.2.3 Authenticated RCE
CVE-2024-47051CRITICAL28 Feb 2025
Remote Code Execution & File Deletion in Asset Uploads
48RISK
open
GitHub PoC1
skrkcb2/CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware27 Feb 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-21333HIGHunder attack27 Feb 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware27 Feb 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC232
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
CVE-2025-21333HIGHunder attack27 Feb 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
cojoben/CVE-2018-13382
CVE-2018-13382CRITICALunder attackransomware26 Feb 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
GitHub PoC6
CVE-2025-26263 - GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
CVE-2025-26263MEDIUM26 Feb 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware26 Feb 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack26 Feb 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-13382CRITICALunder attackransomware26 Feb 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware26 Feb 2025
Information disclosure
100RISK
open
GitHub PoC
Automation script to exploit the Shellshock vulnerability.
CVE-2014-6271CRITICALunder attack26 Feb 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
client-side
CVE-2025-24752HIGH26 Feb 2025
WordPress Essential Addons for Elementor plugin <= 6.0.14 - Reflected Cross Site Scripting (XSS) vulnerability
41RISK
open
GitHub PoC
SpiX-7/CVE-2024-24919-POC
CVE-2024-24919HIGHunder attackransomware26 Feb 2025
Information disclosure
100RISK
open
previouspage 304 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.