Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
13,282 exploits
GitHub PoC1
Playing with CVE-2010-2883
CVE-2010-2883HIGHunder attack22 Sep 2025
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RISK
open
GitHub PoC
ay 09 — CVE-2025-27520 (BentoML-style insecure deserialization) — Local Docker lab
CVE-2025-27520CRITICAL22 Sep 2025
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RISK
open
GitHub PoC1
Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.
CVE-2025-21298CRITICAL22 Sep 2025
Windows OLE Remote Code Execution Vulnerability
70RISK
open
GitHub PoC10
Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022
CVE-2024-32022CRITICAL22 Sep 2025
Kohya_ss is vulnerable to a command injection in basic_caption_gui.py (GHSL-2024-019)
48RISK
open
GitHub PoC1
PoC and exploit scripts for CVE-2023-20048 - Remote Code Execution vulnerability affecting Cisco RV series routers. Includes a vulnerability checker (PoC) and a working exploit for gaining remote shell access. For educational and research purposes only.
CVE-2023-20048CRITICAL22 Sep 2025
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authent
53RISK
open
GitHub PoC
A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)
CVE-2018-7600CRITICALunder attackransomware21 Sep 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC1
iteride/CVE-2025-29927
CVE-2025-29927CRITICAL21 Sep 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC1
A working (at least for me :] ) exploit for CVE-2025-25257
CVE-2025-25257CRITICALunder attack21 Sep 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
GitHub PoC2
CVE-2020-0796 (SMBGhost) is a critical RCE vulnerability in Windows 10 SMBv3 protocol. It allows attackers to execute code remotely via crafted SMB packets, making it wormable. Affects Windows 10 v1903/v1909 and Server 2019. Exploit targets srv2.sys via buffer overflow
CVE-2020-0796CRITICALunder attackransomware21 Sep 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
CVE-2025-10035CRITICALunder attackransomware21 Sep 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RISK
open
GitHub PoC
CVE-2018-13379 - Fortinet SSL VPN Vulnerability
CVE-2018-13379CRITICALunder attackransomware21 Sep 2025
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC2
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
CVE-2025-34152CRITICAL21 Sep 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISK
open
GitHub PoC
sdrtba/CVE-2025-29927
CVE-2025-29927CRITICAL20 Sep 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC19
Detection for CVE-2025-10035
CVE-2025-10035CRITICALunder attackransomware20 Sep 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RISK
open
GitHub PoC1
This is a minimal, educational simulation that demonstrates the _impact_ class of a management-plane parsing RCE (inspired by CVE-2025-20265). It intentionally executes commands from crafted input for local learning only.
CVE-2025-20265CRITICAL20 Sep 2025
Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
53RISK
open
GitHub PoC1
🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.
CVE-2025-32463CRITICALunder attack20 Sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
pucagit/CVE-2025-9074
CVE-2025-9074CRITICAL20 Sep 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
GitHub PoC
A lightweight utility designed to detect and remediate systems affected by CVE-2024-3094, a critical vulnerability impacting [insert affected software/library here if known]. This tool provides automated scanning, reporting, and optional mitigation steps to help administrators and security teams secure their environments quickly.
CVE-2024-3094CRITICAL20 Sep 2025
Xz: malicious code in distributed source
70RISK
open
GitHub PoC13
Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.
CVE-2025-10585HIGHunder attack19 Sep 2025
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr
71RISK
open
GitHub PoC1
CVE-2025-49113 - Roundcube Remote Code Execution
CVE-2025-49113CRITICALunder attack19 Sep 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
WinRAR漏洞CVE-2025-8088的payload一键生成工具
CVE-2025-8088HIGHunder attack18 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC1
Exploit Path Traversal in esm-dev
CVE-2025-59342MEDIUM18 Sep 2025
esm.sh writes arbitrary files via path traversal in `X-Zone-Id` header
48RISK
open
GitHub PoC
HK4zCzi/CVE-2019-3396-Velocity-Server-Side-Template-Injection
CVE-2019-3396CRITICALunder attackransomware18 Sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
There are Exploit for Magnus Billing v7 system get root privilages
CVE-2023-30258CRITICAL18 Sep 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
GitHub PoC1
test
CVE-2025-32433CRITICALunder attack18 Sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC2
This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract credentials using sqlmap (poc_auto_get_username_pass.py). For educational and authorized use only.
CVE-2025-57819CRITICALunder attack18 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC
This tiny lab simulates the core idea behind CVE-2025-29306: unsafe use of `unserialize()` on attacker-controlled input leading to remote code execution.
CVE-2025-29306CRITICAL18 Sep 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
GitHub PoC
veniversum/cve-2025-43300
CVE-2025-43300CRITICALunder attack18 Sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
GitHub PoC1
A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters via GraphQL mutations, and how to detect, analyze, and report the breach using ELK.
CVE-2025-59359CRITICAL18 Sep 2025
OS command injection in Chaos Mesh via the cleanTcs mutation
48RISK
open
GitHub PoC1
Shinkirou789/Cve-2025-8088-WinRar-vulnerability
CVE-2025-8088HIGHunder attack17 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
previouspage 116 / 443next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.