Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
13,264 exploits
GitHub PoC
tinashelorenzi/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware14 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
💥Extension Tool para Auditoría y Explotación avanzada RCE/Source Leak/Dos (CVE-2025-55182/83/84) para entornos Next.js y React Server Components (RSC) directamente desde tu navegador + Laboratorio Vulnerable❌
CVE-2025-55182CRITICALunder attackransomware14 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Check if your server is affected by CVE-2025-55182 & CVE-2025-66478
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
A hybrid security scanner for detecting CVE-2025-55182 in Next.js and Waku applications. Features combined static code analysis and safe dynamic verification for DevSecOps workflows.
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
NodeJS-based exploit script and scanner for the React Server Components "React2Shell" vulnerability (CVE-2025-55182).
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
ZorvithonLeo-Null/CVE-2025-55182-exploit
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
A hands-on lab for understanding and exploiting CVE-2025-55182 (React2Shell) - Remote Code Execution in React Server Components
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
A research report on CVE-2025-55182 (React2Shell).
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Analysis, Validation Environment, and POC for CVE-225-55182 Vulnerability.
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC35
A CVE-2025-55182(React2Shell) Toolbox Application
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
A CLI tool that exploits vulnerabilities in React Server Components and Server Actions (CVE-2025-55182, CVE-2025-66478) to achieve remote code execution (RCE) on vulnerable servers.
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC6
Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE). Includes detailed vulnerability analysis, exploitation techniques, and team learning materials.
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
High-performance Go implementation for detecting React Server Components RCE vulnerabilities (CVE-2025-55182 & CVE-2025-66478).
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
grejh0t/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
A modern Next.js vulnerable web app themed as a news / blog portal for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) to learn, detect, and safely exercise React2Shell. Runs unpatched React 19.0.0 and Next.js 15.0.3.
CVE-2025-55182CRITICALunder attackransomware13 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC27
CVE-2025-8110 PoC
CVE-2025-8110HIGHunder attack13 Dec 2025
File overwrite in file update API in Gogs
100RISK
open
GitHub PoC
Example web application that run on struts2 REST plugin 2.5.8, for demonstration purpose only
CVE-2017-9805HIGHunder attack13 Dec 2025
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC1
CVE-2024-27348 Exploitation Toolkit: Complete RCE exploit for Apache Huge-Graph-Server vulnerability.
CVE-2024-27348CRITICALunder attack13 Dec 2025
Apache HugeGraph-Server: Command execution in gremlin
100RISK
open
GitHub PoC
PoC para explotar el CVE-2024-10914
CVE-2024-10914CRITICAL13 Dec 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
Passive detection for CVE-2025-58360
CVE-2025-58360HIGHunder attack12 Dec 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open
GitHub PoC
Joker-Wiggin/CVE-2025-58360-GeoServer-XXE
CVE-2025-58360HIGHunder attack12 Dec 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open
GitHub PoC
Exploit for CVE-2025-11001
CVE-2025-11001HIGH12 Dec 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC
ryanhafid/PoC_CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware12 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Python port of an ExploitDB proof-of-concept.
CVE-2019-11043HIGHunder attackransomware12 Dec 2025
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC7
CVE-2025-55182 security test kit: CLI scanner + Chrome extension + Nuclei templates + Docker lab.
CVE-2025-55182CRITICALunder attackransomware12 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CVE-2025-55182 – CVE-2025-66478 – React2Shell
CVE-2025-55182CRITICALunder attackransomware12 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
ryanhafid/Scan_CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware12 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC46
Advanced Exploitation Toolkit for Next.js Server Actions (CVE-2025-55182)
CVE-2025-55182CRITICALunder attackransomware12 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2025-55182 の検証用
CVE-2025-55182CRITICALunder attackransomware12 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC5
WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using React Server Components. Designed for CTFs and research, it features a single-command mode, an interactive web CLI, and reverse shell capabilities to demonstrate RCE.
CVE-2025-55182CRITICALunder attackransomware12 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.