Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack04 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL04 Jul 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-46747CRITICALunder attackransomware04 Jul 2025
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-27817HIGH04 Jul 2025
Apache Kafka Client: Arbitrary file read and SSRF vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALunder attack04 Jul 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack04 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack04 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack04 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-20281CRITICALunder attack04 Jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack03 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack03 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack03 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack03 Jul 2025
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
client-side
CVE-2025-6218HIGHunder attack03 Jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2025-49596CRITICAL03 Jul 2025
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISK
open
VulnCheck XDB
initial-access
CVE-2012-1823CRITICALunder attack03 Jul 2025
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack03 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH03 Jul 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack03 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware02 Jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack02 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack02 Jul 2025
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack01 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-20282CRITICAL01 Jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
48RISK
open
VulnCheck XDB
infoleak
CVE-2025-49493MEDIUM01 Jul 2025
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.