Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,150 exploits
VulnCheck XDB
info-leak
CVE-2025-2011HIGH28 Nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL28 Nov 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-26360HIGHunder attack28 Nov 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack27 Nov 2025
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack27 Nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-2198027 Nov 2025
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n
23RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack27 Nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack27 Nov 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
infoleak
CVE-2025-58360HIGHunder attack27 Nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware27 Nov 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALunder attack27 Nov 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALunder attack26 Nov 2025
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-58360HIGHunder attack26 Nov 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-15949HIGHunder attack26 Nov 2025
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware26 Nov 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL26 Nov 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-6389CRITICAL25 Nov 2025
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback
60RISK
open
VulnCheck XDB
local
CVE-2022-37969HIGHunder attack25 Nov 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack25 Nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH24 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
infoleak
CVE-2019-845124 Nov 2025
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALunder attack24 Nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-24054MEDIUMunder attack23 Nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware23 Nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH22 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH22 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack21 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47916CRITICAL21 Nov 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack21 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack20 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.