Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,837cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
13,264 exploits
GitHub PoC
Heuristic security scanner for detecting React Server Components (RSC) vulnerabilities, including React2Shell-style behavior (CVE-2025-55182). Safe, non-exploitative, multi-target capable.
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
jan0x190/CVE-2025-55182-Simple-Scanner-main
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
HUAHUAI23/CVE-2025-55182-POC
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CVE-2025-55182 and CVE-2025-66478
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CVE-2025-55182 Next.js RCE Exploit Tool
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
[React2Hell] Next.js/React Server RCE Exploit — CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Exploit for CVE-2025-55182 (React4Shell)
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
rsp243/fix_nginx_CVE-2013-4547_IB
CVE-2013-454708 Dec 2025
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RISK
open
GitHub PoC
CVE-2025-55182 React2Shell PoC
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Scanner to detect the presence of CVE-2025-55182 & CVE-2025-66478 on targeted web services.
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2025-55182 and CVE-2025-66478
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC8
🔍 Next.js RCE Scanner (CVE-2025-55182) - Automated vulnerability scanner using Zoomeye search engine. Discovers targets via dorks and tests for CVE-2025-55182 with parallel scanning capabilities.
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
alanbarret/CVE-2019-18935
CVE-2019-18935CRITICALunder attackransomware08 Dec 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC3
A Chrome extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
gladiator-07/CVE-2022-0847
CVE-2022-0847HIGHunder attack08 Dec 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
Ngagne-Demba-Dia/CVE-2024-6387-corrigee
CVE-2024-6387HIGH08 Dec 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
CVE-2025-55182-scanner with 2 different method
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Macaroniwdcheese/CVE-2025-55182-Lab
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Alat ini mendeteksi potensi kerentanan React2Shell (CVE-2025-55182) dalam proyek React dengan memeriksa: - File `package.json` dan file lock untuk paket rentan - Direktori `node_modules` untuk dependensi yang terpengaruh - URL secara pasif untuk deteksi jarak jauh
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
VulnCheck CVE-2025-55182 react2shell
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
jandelima/cve-2025-55182-poc-test
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
https://gist.github.com/maple3142/48bc9393f45e068cf8c90ab865c0f5f3
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Drupal vulnerable a CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware08 Dec 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC3
POC and lab setup
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
CVE-2025-55182 React RCE Test Program
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
lalaterry/CVE-2025-55182-React2Shell-lab
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
scanner testing
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
faizdotid/rust-cve-2025-55182
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
A security vulnerability scanner for detecting the React2Shell vulnerability (CVE-2025-55182) in Next.js and React applications.
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2025-55182 + CVE-2025-66478 - Next.js/React Server Components Remote Code Execution
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.