Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
13,264 exploits
GitHub PoC1
Mass Exploit for CVE-2025-29306
CVE-2025-29306CRITICAL07 Jan 2026
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
GitHub PoC1
CVE-2022-0847(Linux 内核本地提权漏洞)
CVE-2022-0847HIGHunder attack07 Jan 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits
CVE-2019-1863407 Jan 2026
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
GitHub PoC
CVE-2025-55182-poc-json
CVE-2025-55182CRITICALunder attackransomware07 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Full automation check for CVE-2025-14847 MonogBleed- Finds origin IP and tests for exploit.
CVE-2025-14847HIGHunder attack07 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
ingress-nginx admission controller RCE escalation PoC
CVE-2025-1974CRITICAL07 Jan 2026
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC1
在python3中运行的脚本
CVE-2018-2628CRITICALunder attack07 Jan 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RISK
open
GitHub PoC
DDestinys/CVE-2023-42793
CVE-2023-42793CRITICALunder attackransomware06 Jan 2026
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC1
CVE-2025-14847 MongoDB Memory Leak Exploit
CVE-2025-14847HIGHunder attack06 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
nishant-kumar-5173/CVE-2024-5932
CVE-2024-5932CRITICAL06 Jan 2026
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
GitHub PoC
CVE-2025-55182, also known as React2Shell, is a critical vulnerability affecting Next.js applications using React Server Components (RSC) and Server Actions.
CVE-2025-55182CRITICALunder attackransomware06 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Exploit for the CVE-2025-37164
CVE-2025-37164CRITICALunder attack06 Jan 2026
A remote code execution issue exists in HPE OneView.
100RISK
open
GitHub PoC
"Once upon a time, the Castle of Reactland trusted all Flight messages... until The Imposter arrived." A storytelling CVE-2025-55182 (React2Shell) demo - Medieval-themed vulnerable React Server Components app for security education.
CVE-2025-55182CRITICALunder attackransomware06 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CVE-2025-52691 Scanner - Detects vulnerable SmarterMail installations (CVSS 10.0 RCE)
CVE-2025-52691CRITICALunder attackransomware05 Jan 2026
Upload Arbitrary Files
100RISK
open
GitHub PoC1
CVE-2025-68926 POC
CVE-2025-68926CRITICAL05 Jan 2026
RustFS has a gRPC Hardcoded Token Authentication Bypass
53RISK
open
GitHub PoC
A hands-on Windows 7 lab designed to demonstrate the real-world impact of the BlueKeep (CVE-2019-0708) vulnerability through practical exploitation and security analysis.
CVE-2019-0708CRITICALunder attackransomware05 Jan 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
Python PoC for Webmin 1.580 Remote Command Execution (CVE-2012-2982)
CVE-2012-298205 Jan 2026
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISK
open
GitHub PoC
next.js rce exploit
CVE-2025-55182CRITICALunder attackransomware05 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
Nextjs RCE Exploit
CVE-2025-55182CRITICALunder attackransomware05 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC79
exploit for cve-2025-43529
CVE-2025-43529HIGHunder attack05 Jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
GitHub PoC2
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
CVE-2025-13390CRITICAL05 Jan 2026
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RISK
open
GitHub PoC
zsy107u/CVE-2025-2011-poc
CVE-2025-2011HIGH05 Jan 2026
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open
GitHub PoC
fixed version
CVE-2021-3156HIGHunder attack05 Jan 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC2
A PoC for CVE-2023-46604 written as part of SPS class for the Advanced Cyber Security master's at UPB.
CVE-2023-46604CRITICALunder attackransomware04 Jan 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
CVE-2017-9805: Apache Struts 2 S2-052 RCE Exploit - PoC for Harvard University (OTD)
CVE-2017-9805HIGHunder attack04 Jan 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC
一个容器逃逸漏洞POC
CVE-2025-9074CRITICAL04 Jan 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
GitHub PoC
Mongobleed Detector CVE-2025-14847
CVE-2025-14847HIGHunder attack04 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
🔍 Discover and scan vulnerable Next.js instances to protect your infrastructure from critical RCE vulnerabilities like CVE-2025-55182.
CVE-2025-55182CRITICALunder attackransomware04 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC10
CVE-2025-68926 - RustFS Hardcoded gRPC Authentication Token Exploit
CVE-2025-68926CRITICAL04 Jan 2026
RustFS has a gRPC Hardcoded Token Authentication Bypass
53RISK
open
GitHub PoC7
React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the Flight protocol.
CVE-2025-55182CRITICALunder attackransomware04 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.