Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
13,264 exploits
GitHub PoC68
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
CVE-2025-33073HIGHunder attack14 Nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1
PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version, health, and database info. For security research and defensive validation only.
CVE-2025-64513CRITICAL14 Nov 2025
Milvus Proxy has Critical Authentication Bypass Vulnerability
48RISK
open
GitHub PoC7
# CVE-2025-64446 PoC - FortiWeb Path Traversal Proof of Concept para la vulnerabilidad de path traversal en Fortinet FortiWeb que permite ejecución remota de comandos. Incluye herramienta de detección para fines educativos. **⚠️ SOLO USO EDUCATIVO - NO PARA EXPLOTACIÓN ⚠️**
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC13
sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC32
CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploited as a zero-day.
CVE-2025-62215HIGHunder attack14 Nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
CVE-2022-22965 proof of concept for CS4239 report
CVE-2022-22965CRITICALunder attack14 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC14
Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel security research
CVE-2025-7771HIGH13 Nov 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC6
PoC Exploit CVE-2018-6389
CVE-2018-638913 Nov 2025
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC
keyuraghao/CVE-2025-20260
CVE-2025-20260CRITICAL13 Nov 2025
ClamAV PDF Scanning Buffer Overflow Vulnerability
48RISK
open
GitHub PoC
cyhe50/cve-2025-32434-poc
CVE-2025-32434CRITICAL13 Nov 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RISK
open
GitHub PoC24
redpack-kr/CVE-2025-60710
CVE-2025-60710HIGHunder attack12 Nov 2025
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
Alex-Acero-Security/CVE-2024-48910-POC
CVE-2024-48910CRITICAL12 Nov 2025
DOMPurify vulnerable to tampering by prototype polution
48RISK
open
GitHub PoC8
CVE-2025-55315 PoC Exploit
CVE-2025-55315CRITICAL11 Nov 2025
ASP.NET Security Feature Bypass Vulnerability
60RISK
open
GitHub PoC2
CVE-2025-48703 é uma vulnerabilidade de Execução Remota de Código (RCE) no módulo filemanager de um painel de hospedagem web (por exemplo, cPanel). Ocorre devido ao tratamento de entrada não sanitizado na função acc=changePerm, que permite que um atacante injete e execute comandos.
CVE-2025-48703CRITICALunder attack11 Nov 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
GitHub PoC
CVE-2025-21042
CVE-2025-21042HIGHunder attack11 Nov 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
76RISK
open
GitHub PoC1
Comprehensive Proof of Concept collection for CVE-2025-11953, CVE-2025-59287, CVE-2025-8941 with exploitation frameworks in Python, C, Bash, PowerShell
CVE-2025-11953CRITICALunder attack11 Nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISK
open
GitHub PoC
Exploit cyberpanel version 2.3.6 - 2.3.7
CVE-2024-51378CRITICALunder attackransomware11 Nov 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISK
open
GitHub PoC2
CVE-2025-41244 is a critical local privilege escalation vulnerability in VMware Aria Operations and VMware Tools
CVE-2025-41244HIGHunder attack11 Nov 2025
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RISK
open
GitHub PoC2
AstrBot老版本RCE
CVE-2025-55449HIGH11 Nov 2025
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key us
41RISK
open
GitHub PoC
Detection for CVE-2025-34299
CVE-2025-34299CRITICAL11 Nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
GitHub PoC5
Wh04m1001/CVE-2025-60710
CVE-2025-60710HIGHunder attack11 Nov 2025
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
harekrishnarai/CVE-2024-23897-test-windows
CVE-2024-23897CRITICALunder attackransomware11 Nov 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
Vulnerability for Xwiki
CVE-2024-31982CRITICAL11 Nov 2025
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RISK
open
GitHub PoC2
Mitchellzhou1/CVE-2024-48910-PoC
CVE-2024-48910CRITICAL11 Nov 2025
DOMPurify vulnerable to tampering by prototype polution
48RISK
open
GitHub PoC
CVE-2025-25257 PoC for educational use and/or authorised pentesting.
CVE-2025-25257CRITICALunder attack11 Nov 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
GitHub PoC
Exploit and test stand for CVE-2025-2945
CVE-2025-2945CRITICAL10 Nov 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISK
open
GitHub PoC1
check if vulnerable python-django version to CVE-2025-64459 bug
CVE-2025-64459CRITICAL10 Nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open
GitHub PoC1
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
CVE-2025-6440CRITICAL10 Nov 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
Ghstxz/CVE-2025-32463
CVE-2025-32463CRITICALunder attack10 Nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
A proof of concept for CVE-2025-24054/CVE-2025-24071
CVE-2025-24054MEDIUMunder attack09 Nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
previouspage 109 / 443next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.