Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALunder attack04 Sep 2025
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-5016404 Sep 2025
Apache Struts: File upload component had a directory traversal vulnerability
45RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-53772HIGH04 Sep 2025
Web Deploy Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack04 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALunder attack04 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
local
CVE-2024-1086HIGHunder attackransomware04 Sep 2025
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack03 Sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
VulnCheck XDB
local
CVE-2015-132803 Sep 2025
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware03 Sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH03 Sep 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack03 Sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-51568CRITICAL02 Sep 2025
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-34300CRITICAL01 Sep 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack01 Sep 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALunder attack01 Sep 2025
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL01 Sep 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALunder attack01 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11357CRITICALunder attackransomware01 Sep 2025
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware01 Sep 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3515HIGH01 Sep 2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RISK
open
VulnCheck XDB
initial-access
CVE-2018-1920701 Sep 2025
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISK
open
VulnCheck XDB
client-side
CVE-2015-925131 Aug 2025
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RISK
open
VulnCheck XDB
local
CVE-2025-7771HIGH31 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack31 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware31 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-48307CRITICAL31 Aug 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RISK
open
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALunder attackransomware30 Aug 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack30 Aug 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack29 Aug 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-34040CRITICAL29 Aug 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.