Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
75,432 exploits
GitHub PoC
MongoBleed CVE-2025-14847 Vulnerability Checker
CVE-2025-14847HIGHunder attack01 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC3
CVE-2025-68645 - A Local File Inclusion (LFI) vulnerability in the Webmail Classic UI of Zimbra Collaboration
CVE-2025-68645HIGHunder attack01 Jan 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
GitHub PoC
galois17/cve-2017-12149-playground
CVE-2017-12149CRITICALunder attackransomware01 Jan 2026
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RISK
open
GitHub PoC
CVE-2025-52691
CVE-2025-52691CRITICALunder attackransomware01 Jan 2026
Upload Arbitrary Files
100RISK
open
GitHub PoC3
Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into safe.txt.
CVE-2025-54068CRITICALunder attack01 Jan 2026
Livewire vulnerable to remote command execution during property update hydration
100RISK
open
GitHub PoC
A custom Python proof-of-concept showcasing root-cause analysis and exploitation of CVE 2019-9978 (Social Warfare plugin),focusing on practical RFI to RCE attack flow.
CVE-2019-9978MEDIUMunder attack01 Jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC
ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability. החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook
CVE-2024-21413CRITICALunder attack01 Jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-68645HIGHunder attack01 Jan 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
VulnCheck XDB
info-leak
CVE-2025-30208MEDIUM01 Jan 2026
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH31 Dec 2025
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
GitHub PoC2
nkuty/CVE-2025-54322-exploit
CVE-2025-54322CRITICAL31 Dec 2025
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
53RISK
open
GitHub PoC
Rishi-kaul/CVE-2025-14847-MongoBleed
CVE-2025-14847HIGHunder attack31 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC1
A new way to exploit CVE-2025-58360 bypass WAF
CVE-2025-58360HIGHunder attack31 Dec 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open
VulnCheck XDB
info-leak
CVE-2018-1171431 Dec 2025
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00
35RISK
open
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALunder attackransomware31 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade vers Root (SUID). Ce dépôt contient le rapport technique détaillé, les preuves d'exploitation (PoC) et les mesures de remédiation pour sécuriser l'infrastructure.
CVE-2014-370431 Dec 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
GitHub PoC5
Poc for CVE-2025-7771 to modify PPL Protection
CVE-2025-7771HIGH31 Dec 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC
Goultarde/CVE-2025-55182-React2Shell-Lab
CVE-2025-55182CRITICALunder attackransomware31 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware30 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It demonstrates how the exploit works, including the payload and impact.
CVE-2025-55182CRITICALunder attackransomware30 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
🎯 Automated vulnerability scanner for React2Shell RCE - Google dorking + safe detection for CVE-2025-55182/CVE-2025-66478 (CVSS 10.0)
CVE-2025-55182CRITICALunder attackransomware30 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Udyz/CVE-2025-52691
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC
cve-2025-54236 poc
CVE-2025-54236CRITICALunder attack30 Dec 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
GitHub PoC2
Academic proof-of-concept demonstrating CVE-2025-68645 for authorized security research.
CVE-2025-68645HIGHunder attack30 Dec 2025
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
GitHub PoC1
This repo contains my python script version of CVE-2025-14847 (MongoBleed)
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC1
CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Remake of CVE-2025-14847 MongoDB vulnerability demonstration
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE
CVE-2020-0796CRITICALunder attackransomware30 Dec 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
previouspage 145 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.