Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL02 Aug 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL02 Aug 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISK
open
VulnCheck XDB
initial-access
CVE-2024-2053HIGH02 Aug 2025
Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-4606CRITICAL02 Aug 2025
Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-48703CRITICALunder attack01 Aug 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
VulnCheck XDB
local
CVE-2025-48384HIGHunder attack01 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack01 Aug 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-23752MEDIUMunder attack31 Jul 2025
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALunder attack31 Jul 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL31 Jul 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-51482HIGH31 Jul 2025
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem
56RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack30 Jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
local
CVE-2023-22809HIGH30 Jul 2025
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
client-side
CVE-2023-2533HIGHunder attack30 Jul 2025
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
76RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack30 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack29 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHunder attackransomware29 Jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL29 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware29 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack28 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware28 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware28 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL28 Jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL28 Jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware27 Jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware27 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack27 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack26 Jul 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-32429CRITICAL26 Jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open
VulnCheck XDB
client-side
CVE-2023-23397CRITICALunder attack25 Jul 2025
Microsoft Outlook Elevation of Privilege Vulnerability
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.