Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
remote-with-credentials
CVE-2025-1094HIGH19 Oct 2025
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack19 Oct 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-2812119 Oct 2025
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RISK
open
VulnCheck XDB
local
CVE-2025-33073HIGHunder attack18 Oct 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
infoleak
CVE-2024-27956CRITICAL17 Oct 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack17 Oct 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2017-100036717 Oct 2025
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack17 Oct 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2022-1364HIGHunder attack16 Oct 2025
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit
76RISK
open
VulnCheck XDB
local
CVE-2025-24990HIGHunder attack16 Oct 2025
Windows Agere Modem Driver Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL15 Oct 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware15 Oct 2025
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-2476215 Oct 2025
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH15 Oct 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH14 Oct 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack14 Oct 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-7441CRITICAL14 Oct 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack14 Oct 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
client-side
CVE-2025-4123HIGH14 Oct 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack14 Oct 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
VulnCheck XDB
infoleak
CVE-2025-61884HIGHunder attackransomware13 Oct 2025
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-1254213 Oct 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
VulnCheck XDB
local
CVE-2023-29360HIGHunder attack12 Oct 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
infoleak
CVE-2024-46982HIGH11 Oct 2025
Cache Poisoning in next.js
53RISK
open
VulnCheck XDB
initial-access
CVE-2025-11371HIGHunder attack11 Oct 2025
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-5947CRITICAL10 Oct 2025
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISK
open
VulnCheck XDB
infoleak
CVE-2025-2539HIGH10 Oct 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack10 Oct 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-61882CRITICALunder attackransomware10 Oct 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-49844CRITICAL09 Oct 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.