Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
75,432 exploits
GitHub PoC
nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE
CVE-2020-0796CRITICALunder attackransomware30 Dec 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Udyz/CVE-2025-52691
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC1
CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC1
This repo contains my python script version of CVE-2025-14847 (MongoBleed)
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
cve-2025-54236 poc
CVE-2025-54236CRITICALunder attack30 Dec 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
GitHub PoC
Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471
CVE-2022-40471CRITICAL30 Dec 2025
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RISK
open
GitHub PoC
CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules
CVE-2024-4577CRITICALunder attackransomware30 Dec 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54236CRITICALunder attack30 Dec 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
GitHub PoC2
Academic proof-of-concept demonstrating CVE-2025-68645 for authorized security research.
CVE-2025-68645HIGHunder attack30 Dec 2025
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware30 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALunder attackransomware29 Dec 2025
Upload Arbitrary Files
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware29 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Reproducible Docker lab for CVE-2018-15133 (Laravel Framework token unserialize RCE)
CVE-2018-15133HIGHunder attack29 Dec 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
amirali-ramezani/react2shell-CVE-2025-55182-
CVE-2025-55182CRITICALunder attackransomware29 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack29 Dec 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-14611HIGHunder attack29 Dec 2025
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
CVE-2025-14611 CentreStack and Triofox full Poc/Exploit
CVE-2025-14611HIGHunder attack29 Dec 2025
Gladinet CentreStack and TrioFox Hard Coded AES Keys
98RISK
open
GitHub PoC13
Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC4
Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Rishi-kaul/n8n-CVE-2025-68613
CVE-2025-68613CRITICALunder attack29 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC
MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC3
CVE-2025-14847 (MongoBleed)
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
cv-sai-kamesh/n8n-CVE-2025-68613
CVE-2025-68613CRITICALunder attack29 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC1
CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
previouspage 146 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.