Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
13,264 exploits
GitHub PoC8
基于 CVE-2025-55182 漏洞检测 burpsuite 被动扫描插件
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Y3B3L4Y3/CVE-2025-55182-test
CVE-2025-55182CRITICALunder attackransomware05 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
A proof of concept exploit script for CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
A proof of concept of remote code execution
CVE-2025-48384HIGHunder attack04 Dec 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC2
React2Shell Scanner (CVE-2025-55182 & CVE-2025-66478)
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC10
Nuclei template for detecting react2shell (CVE-2025-55182 & CVE-2025-66478)
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC21
MrR0b0t19/CVE-2025-55182-shellinteractive
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC24
Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC4
some notes && (somewhat?) poc-adjacent stuff for CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
0xPThree/cve-2025-55182
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
clevernyyyy/CVE-2025-55182-Dockerized
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Functional Python POC to test if servers are vulnerable to CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
PoC CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC7
Deliberately vulnerable banking app for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) to learn, detect, and safely exercise React2Shell. Runs unpatched React 19.0.0 and Next.js 15.0.3.
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
klassiker/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Unified Security Research Tool
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC6
Scanner for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Track and remediate a critical React Server Components (RSC) / Flight protocol vulnerability campaign impacting react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack, and RSC-enabled frameworks like Next.js.
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC5
Poc for CVE-2025-55182 (remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages)
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Docker test environment for CVE-2025-13486 (ACF Extended RCE). For security research only.
CVE-2025-13486CRITICAL04 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC2
Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC5
POC for CVE-2025-13486
CVE-2025-13486CRITICAL04 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC
Vulnerable setup for CVE-2025-13486 - Advanced Custom Fields: Extended - Remote Code Execution
CVE-2025-13486CRITICAL04 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC
Vulnerable REACT app in docker container and poc code - for demos
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC8
Actual CVE-2025-55182 detection and exploit. No bullshit LLMs.
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test and understand the vulnerability.
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
zr0n/CVE-2025-48384-sub
CVE-2025-48384HIGHunder attack04 Dec 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC117
Next.js-Exploit-Tool 图形化综合利用工具,基于 Go 开发,一款针对 CVE-2025-55182 的独立安全评估工具。
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
检测针对 CVE-2025-55182(React 服务器组件远程代码执行漏洞)的扫描器
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC58
Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Auto-fix, SARIF output, GitHub Actions, Vercel integration, and runtime protection middleware.
CVE-2025-55182CRITICALunder attackransomware04 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Wercd/CVE-2021-26855
CVE-2021-26855CRITICALunder attackransomware04 Dec 2025
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
previouspage 103 / 443next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.