Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
initial-access
CVE-2025-34040CRITICAL29 Aug 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-12877CRITICAL28 Aug 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack28 Aug 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL28 Aug 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack28 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack28 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack27 Aug 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack27 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack27 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack27 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack27 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
local
CVE-2018-19323CRITICALunder attackransomware27 Aug 2025
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
78RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
local
CVE-2019-6693MEDIUMunder attackransomware26 Aug 2025
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-34030CRITICAL26 Aug 2025
sar2html OS Command Injection
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware25 Aug 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack25 Aug 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware25 Aug 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack25 Aug 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH25 Aug 2025
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
VulnCheck XDB
client-side
CVE-2025-5419HIGHunder attack25 Aug 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack24 Aug 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864624 Aug 2025
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
local
CVE-2025-43300CRITICALunder attack24 Aug 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
VulnCheck XDB
client-side
CVE-2025-33053HIGHunder attack23 Aug 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-36847CRITICAL23 Aug 2025
Simple File List < 4.2.3 - Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALunder attack23 Aug 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack22 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.