Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
8,176 exploits
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack27 Apr 2025
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288927 Apr 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-27956CRITICAL27 Apr 2025
WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-15133HIGHunder attack27 Apr 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack27 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMunder attack27 Apr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2017-8291HIGHunder attack27 Apr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-8291HIGHunder attack27 Apr 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware27 Apr 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL26 Apr 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
VulnCheck XDB
client-side
CVE-2021-41773HIGHunder attackransomware26 Apr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-39361CRITICAL26 Apr 2025
Unauthenticated SQL Injection in graph_view.php in Cacti
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALunder attack26 Apr 2025
Craft CMS Allows Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-1389HIGHunder attack26 Apr 2025
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability i
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH25 Apr 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL25 Apr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-32433CRITICALunder attack25 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALunder attack25 Apr 2025
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL25 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware25 Apr 2025
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-282524 Apr 2025
35RISK
open
VulnCheck XDB
infoleak
CVE-2025-34028CRITICALunder attack24 Apr 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALunder attack24 Apr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware24 Apr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL24 Apr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware24 Apr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware24 Apr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.