Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack09 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack08 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware08 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware08 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-9014CRITICAL08 Jul 2025
OAuth2 client id and secret exposed through the web browser in pgAdmin 4
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-7954CRITICAL08 Jul 2025
SPIP porte_plume Plugin Arbitrary PHP Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-48703CRITICALunder attack07 Jul 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack07 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack07 Jul 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack07 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2022-37969HIGHunder attack06 Jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware06 Jul 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-2564606 Jul 2025
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware06 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware06 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH06 Jul 2025
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-55963MEDIUM06 Jul 2025
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
38RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-20281CRITICALunder attack06 Jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL06 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack05 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware05 Jul 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack05 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
VulnCheck XDB
infoleak
CVE-2025-49493MEDIUM05 Jul 2025
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.