Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
13,282 exploits
GitHub PoC
mouftan/CVE-2022-44268
CVE-2022-44268MEDIUM31 Jul 2025
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC
KiPhuong/challenge-cve-2024-3552
CVE-2024-3552CRITICAL31 Jul 2025
Web Directory Free < 1.7.0 - Unauthenticated SQL Injection
75RISK
open
GitHub PoC4
CVE‑2025‑5394 WP Alone ≤ 7.8.3
CVE-2025-5394CRITICAL31 Jul 2025
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISK
open
GitHub PoC
maxntv/CVE-2023-22894-PoC
CVE-2023-22894CRITICAL31 Jul 2025
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RISK
open
GitHub PoC
Real-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.
CVE-2017-5638CRITICALunder attackransomware30 Jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC21
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-29824HIGHunder attackransomware30 Jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC1
Automates vulnerability check for sudo versions and privilege escalation via sudoedit if exploitable, helping users test and gain root access.
CVE-2023-22809HIGH30 Jul 2025
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
GitHub PoC
Technical Details and Exploit for CVE-2025-50460
CVE-2025-50460CRITICAL30 Jul 2025
A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization i
48RISK
open
GitHub PoC1
Technical Details and Exploit for CVE-2025-50472
CVE-2025-50472CRITICAL30 Jul 2025
The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untruste
48RISK
open
GitHub PoC
CitrixBleed 2 NetScaler honeypot logs
CVE-2025-5777CRITICALunder attackransomware30 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC4
本项目基于 Docker 搭建了一个用于复现和测试 sudo 本地权限提升漏洞 CVE-2025-32463 的实验环境。
CVE-2025-32463CRITICALunder attack30 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data.
CVE-2025-14847HIGHunder attack30 Jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC2
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, leveraging directory traversal for remote code execution.
CVE-2025-54769HIGH30 Jul 2025
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RISK
open
GitHub PoC
rgvillanueva28/vulnbox-easy-CVE-2025-29927
CVE-2025-29927CRITICAL30 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Combined PoCs for rConfig: SQL Injection (CVE-2020-10220) & Command Injection (CVE-2020-10879)
CVE-2020-1022030 Jul 2025
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RISK
open
GitHub PoC
→ poc for CVE-2025-29927
CVE-2025-29927CRITICAL29 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC2
CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit
CVE-2025-32463CRITICALunder attack29 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Ai相关
CVE-2025-54381CRITICAL29 Jul 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RISK
open
GitHub PoC
Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original Exploit‑DB PoC for educational and authorized testing purposes only.
CVE-2021-43857CRITICAL29 Jul 2025
Gerapy may contain remote code execution vulnerability
60RISK
open
GitHub PoC4
Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC
CVE-2025-53770CRITICALunder attackransomware29 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
DLL00P/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware29 Jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.
CVE-2025-8191MEDIUM28 Jul 2025
macrozheng mall Swagger UI index.html cross site scripting
33RISK
open
GitHub PoC
🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.
CVE-2025-53770CRITICALunder attackransomware28 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
Exploit for CVE-2022-35411 — Unauthenticated RCE in rpc.py (<= 0.6.0)
CVE-2022-3541128 Jul 2025
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i
35RISK
open
GitHub PoC
imbas007/CVE-2025-32429-Checker
CVE-2025-32429CRITICAL28 Jul 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RISK
open
GitHub PoC
r0otk3r/CVE-2025-2294
CVE-2025-2294CRITICAL28 Jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC1
The vulnerability was found by Rich Mirch. More details on it here: https://cxsecurity.com/issue/WLB-2025070022
CVE-2025-32462LOW28 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC2
Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)
CVE-2025-34077CRITICAL28 Jul 2025
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
63RISK
open
GitHub PoC
Tools for detecting and assessing systems vulnerable to CVE-2025-53770 (CWE-502: Deserialization of Untrusted Data).
CVE-2025-53770CRITICALunder attackransomware28 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
r3xbugbounty/CVE-2025-53770
CVE-2025-53770CRITICALunder attackransomware28 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
previouspage 129 / 443next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.