Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
13,282 exploits
GitHub PoC
CVE-2024-32113-Apache-OFBiz<18.12.13-Exploit
CVE-2024-32113CRITICALunder attack09 Oct 2025
Apache OFBiz: Path traversal leading to RCE
100RISK
open
GitHub PoC1
Reproduction and fix of the CVE-2025-29927 vulnerability.
CVE-2025-29927CRITICAL08 Oct 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
lastvocher/Hikvision-CVE-2017-7921-decryptor
CVE-2017-7921CRITICALunder attack08 Oct 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1
CVE-2025-44823CRITICAL07 Oct 2025
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi
53RISK
open
GitHub PoC1
Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security research
CVE-2024-39309CRITICAL07 Oct 2025
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
53RISK
open
GitHub PoC
Remote Code Execution PoC for Apache 2.4.49
CVE-2021-41773HIGHunder attackransomware07 Oct 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
hybinn/CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware06 Oct 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC1
compiled poc binary
CVE-2024-30088HIGHunder attackransomware06 Oct 2025
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
exploit for CVE-2018-16763
CVE-2018-1676305 Oct 2025
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
GitHub PoC
shoucheng3/apache__struts_CVE-2020-17530_2-5-25
CVE-2020-17530CRITICALunder attack05 Oct 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC
WP-CVE-2025-6934 | Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL05 Oct 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
GitHub PoC
Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)
CVE-2020-1472MEDIUMunder attackransomware04 Oct 2025
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC2
An Python Exp For "GeoServer"
CVE-2024-36401CRITICALunder attack04 Oct 2025
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC12
Arbitrary Function Call Exploit using the ThrottleStop driver
CVE-2025-7771HIGH03 Oct 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC13
watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242
CVE-2025-9242CRITICALunder attack01 Oct 2025
WatchGuard Firebox iked Out of Bounds Write Vulnerability
100RISK
open
GitHub PoC
CS50 Cybersecurity final project — Palo Alto OAuth token breach (CVE-2024-3400)
CVE-2024-3400CRITICALunder attackransomware01 Oct 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
tno01/cve-2019-3396
CVE-2019-3396CRITICALunder attackransomware30 Sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC1
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALunder attack30 Sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
GitHub PoC3
ticofookfook/CVE-2025-43300
CVE-2025-43300CRITICALunder attack30 Sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
GitHub PoC
Tnot123/cve-2017-9822
CVE-2017-9822HIGHunder attackransomware30 Sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISK
open
GitHub PoC1
Detection for CVE-2025-41244
CVE-2025-41244HIGHunder attack30 Sep 2025
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RISK
open
GitHub PoC
A Python exploit for CVE-2025-32463, a critical local privilege escalation vulnerability in the Sudo binary on Linux systems. This flaw allows local users to obtain root access by exploiting the --chroot option, which incorrectly uses /etc/nsswitch.conf from a user-controlled directory.
CVE-2025-32463CRITICALunder attack30 Sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
A Rust implementation of the POC for CVE-2017-7269, targeting the WebDAV service in Microsoft Internet Information Services (IIS) 6.0.
CVE-2017-7269CRITICALunder attack30 Sep 2025
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC
victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320
CVE-2025-53770CRITICALunder attackransomware29 Sep 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2024-47051
CVE-2024-47051CRITICAL29 Sep 2025
Remote Code Execution & File Deletion in Asset Uploads
48RISK
open
GitHub PoC
Log4Shell (CVE-2021-44228) PoC
CVE-2021-44228CRITICALunder attackransomware29 Sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
ethan-repo-lab4b6/CVE-2022-36537
CVE-2022-36537HIGHunder attackransomware28 Sep 2025
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISK
open
GitHub PoC
kuyrathdaro/cve-2025-29927
CVE-2025-29927CRITICAL28 Sep 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
0xDTC/CrushFTP-auth-bypass-CVE-2025-31161
CVE-2025-31161CRITICALunder attackransomware27 Sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC
A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.
CVE-2009-226527 Sep 2025
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
previouspage 114 / 443next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.