Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
13,307 exploits
GitHub PoC
A Python-based Exploit Script for CVE-2016-3088
CVE-2016-3088CRITICALunder attack16 Jun 2025
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
GitHub PoC4
SolarWinds Serv-U 15.4.2 HF1 - Directory Traversal
CVE-2024-28995HIGHunder attack15 Jun 2025
SolarWinds Serv-U L Directory Transversal Vulnerability
100RISK
open
GitHub PoC2
CrushFTP 11.3.1 - Authentication Bypass
CVE-2025-31161CRITICALunder attackransomware15 Jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC2
Fortra GoAnywhere MFT 7.4.1 - Authentication Bypass
CVE-2024-0204CRITICAL15 Jun 2025
Authentication Bypass in GoAnywhere MFT
85RISK
open
GitHub PoC8
This project is a research-oriented and educational simulation designed to demonstrate the concept of a sandbox escape vulnerability within Google Chrome (version 134.0.6998.177), leveraging improper handle , validation via Mojo IPC.
CVE-2025-2783HIGHunder attack15 Jun 2025
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open
GitHub PoC3
CVE-2024-4577.py
CVE-2024-4577CRITICALunder attackransomware15 Jun 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Exerrdev/CVE-2024-9264-Fixed
CVE-2024-9264CRITICAL15 Jun 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC3
CVE-2023-1698 exploit with golang
CVE-2023-1698CRITICAL15 Jun 2025
WAGO: WBM Command Injection in multiple products
85RISK
open
GitHub PoC2
Checks if your Chrome version is vulnerable to CVE-2025-5419, from the browser
CVE-2025-5419HIGHunder attack14 Jun 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISK
open
GitHub PoC1
grass341/CVE-2022-37969
CVE-2022-37969HIGHunder attack14 Jun 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
maqeel-git/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware14 Jun 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
This Python script checks for the presence of CVE-2024-40898, a critical vulnerability in Apache HTTP Server that may allow SSL/TLS certificate verification bypass under certain misconfigurations. It initiates an SSL connection to the target server and sends a HEAD request.
CVE-2024-40898CRITICAL14 Jun 2025
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
48RISK
open
GitHub PoC
MAHABUB122003/Atlassian-CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware14 Jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC1
LipeOzyy/CVE-2010-1872-BlazeDVD-SEH-Exploit
CVE-2010-187214 Jun 2025
Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject a
23RISK
open
GitHub PoC
CVE-2014-6271(RCE) poc Exploit
CVE-2014-6271CRITICALunder attack14 Jun 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC705
PoC Exploit for the NTLM reflection SMB flaw.
CVE-2025-33073HIGHunder attack13 Jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1
CVE-2025-24071: NTLMv2 Hash Disclosure via .library-ms File
CVE-2025-24071MEDIUM13 Jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
Privilege Escalation on HTB "Poison" using PwnKit (CVE-2021-4034)
CVE-2021-4034HIGHunder attack13 Jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
CVE-2017-8291 CTF with docker and examples
CVE-2017-8291HIGHunder attack13 Jun 2025
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RISK
open
GitHub PoC
Stored XSS in Nagios Log Server 2024R1.3.1
CVE-2025-29471HIGH13 Jun 2025
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code
41RISK
open
GitHub PoC
CVE-2025-31650
CVE-2025-31650HIGH13 Jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISK
open
GitHub PoC
CVE-2025-31650
CVE-2025-31650HIGH13 Jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISK
open
GitHub PoC
PoC for CVE-2021-29447
CVE-2021-29447HIGH12 Jun 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC
In this lab I walked through an end-to-end intrusion that began with an external RDP break-in, used a brand-new CLFS privilege-escalation exploit (CVE-2024–49138), and ended with SYSTEM-level cloud credential harvesting. Below is the story, the evidence, and the lessons I drew from it.
CVE-2024-49138HIGHunder attack12 Jun 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC64
CVE-2025-33053 Proof Of Concept (PoC)
CVE-2025-33053HIGHunder attack12 Jun 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Gigamon Unauth RCE (CVE-2026-36848)
CVE-2026-36848HIGH12 Jun 2025
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
41RISK
open
GitHub PoC
amitlttwo/Next.JS-CVE-2025-29927
CVE-2025-29927CRITICAL12 Jun 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell (CVE-2022-22965). Local Docker-based setup.
CVE-2022-22965CRITICALunder attack11 Jun 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
KimJuhyeong95/cve-2025-24514
CVE-2025-24514HIGH11 Jun 2025
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
68RISK
open
GitHub PoC
Exploiting the vulnerability called "Dirty_Sock" (CVE-2019-7304) in the REST API for Canonical's snapd daemon.
CVE-2019-7304HIGH11 Jun 2025
Local privilege escalation via snapd socket
53RISK
open
previouspage 143 / 444next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.