Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
13,282 exploits
GitHub PoC4
How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX
CVE-2025-29774CRITICAL23 Jul 2025
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RISK
open
GitHub PoC1
PoC exploit for CVE-2025-7766 – XXE vulnerability leading to potential RCE.
CVE-2025-7766HIGH23 Jul 2025
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RISK
open
GitHub PoC
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771
CVE-2025-53770CRITICALunder attackransomware23 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over testing parameters, multiple attack patterns, and advanced monitoring capabilities.
CVE-2023-44487HIGHunder attack23 Jul 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
GitHub PoC
wyyazjjl/CVE-2024-45195
CVE-2024-45195CRITICALunder attack23 Jul 2025
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
100RISK
open
GitHub PoC5
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition)
CVE-2025-53770CRITICALunder attackransomware23 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
PoC for CVE-2025-5777 – Auth Bypass and RCE in Trend Micro Apex Central
CVE-2025-5777CRITICALunder attackransomware23 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC1
Nuclei template to detect CVE-2024-6387. All latest patched versions are excluded.
CVE-2024-6387HIGH23 Jul 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
CVE-2021-45046CRITICALunder attackransomware23 Jul 2025
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC
shan0ar/cve-2025-32756
CVE-2025-32756CRITICALunder attack23 Jul 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open
GitHub PoC
Proof-of-concept LFI Scanner: Automated detection of /etc/passwd exposures via directory traversal and regex matching.
CVE-2017-12637HIGHunder attack23 Jul 2025
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RISK
open
GitHub PoC1
WordPress联系表单插件 - 未授权任意文件上传漏洞
CVE-2015-10137CRITICAL23 Jul 2025
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RISK
open
GitHub PoC
Skac44/CVE-2024-38063
CVE-2024-38063CRITICAL23 Jul 2025
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC5
CVE-2024-4577 Mass Scanner & Exploit Tool
CVE-2024-4577CRITICALunder attackransomware23 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
CVE-2022-4288923 Jul 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC1
Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)
CVE-2025-6082MEDIUM22 Jul 2025
Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure
33RISK
open
GitHub PoC1
gmh5225/CVE-2025-6558-exp
CVE-2025-6558HIGHunder attack22 Jul 2025
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
71RISK
open
GitHub PoC1
tripoloski1337/CVE-2025-53770-scanner
CVE-2025-53770CRITICALunder attackransomware22 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
PoC exploit for CVE-2025-47917: Use-After-Free in mbedTLS leading to remote code execution.
CVE-2025-47917HIGH22 Jul 2025
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RISK
open
GitHub PoC
Gogs Under Attack: Unpacking the Critical SSH Vulnerability (CVE-2024–39930)
CVE-2024-39930CRITICAL22 Jul 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISK
open
GitHub PoC1
imbas007/CVE-2025-53770-Vulnerable-Scanner
CVE-2025-53770CRITICALunder attackransomware22 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
A Python-based reconnaissance scanner for safely identifying potential exposure to SharePoint vulnerability CVE-2025-53770.
CVE-2025-53770CRITICALunder attackransomware22 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
cve-2024-32002
CVE-2024-32002CRITICAL22 Jul 2025
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
JinParkmida/cve-2023-28771-demo
CVE-2023-28771CRITICALunder attack22 Jul 2025
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RISK
open
GitHub PoC
GreenForceNetworks/Toolshell_CVE-2025-53770
CVE-2025-53770CRITICALunder attackransomware22 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALunder attack22 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)
CVE-2025-53770CRITICALunder attackransomware22 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC11
A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw CVE-2025-49706.
CVE-2025-53770CRITICALunder attackransomware22 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC58
Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)
CVE-2025-53770CRITICALunder attackransomware22 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Reverse Shell CVE for iDRAC 7 & 8 with firmware 2.52.52.52 and below.
CVE-2018-120722 Jul 2025
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute
60RISK
open
previouspage 131 / 443next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.