Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
75,445 exploits
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware20 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-37164CRITICALunder attack19 Dec 2025
A remote code execution issue exists in HPE OneView.
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
Metasploit300
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
CVE-2025-14847HIGHunder attack19 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34442MEDIUM19 Dec 2025
AVideo < 20.1 System Path Disclosure via Public API
28RISK
open
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34441MEDIUM19 Dec 2025
AVideo < 20.1 User Information Disclosure via Public API
28RISK
open
Metasploit600
AVideo notify.ffmpeg.json.php Unauthenticated RCE via Salt Discovery
CVE-2025-34433CRITICAL19 Dec 2025
AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt
63RISK
open
GitHub PoC
PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain, featuring optional proxy support, automated session elevation, and dynamic command injection via the print scripting engine. Designed for security auditing and authorized penetration testing.
CVE-2023-27350CRITICALunder attackransomware19 Dec 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware19 Dec 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-13486CRITICAL19 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC
A Python-based security scanner for detecting and exploiting **React Server Components (RSC)** vulnerabilities in Next.js applications. This tool performs passive detection, active fingerprinting, and RCE exploitation testing.
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
lamaper/CVE-2025-55182-Toolbox
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
React2Shell vulnerability (CVE-2025-55182 / CVE-2025-66478) Full Script
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
open-flaw/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack19 Dec 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC16
Detection for CVE-2025-68461
CVE-2025-68461HIGHunder attack19 Dec 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RISK
open
GitHub PoC1
CVE-2025-13486 - Remote Code Execution & Privilege Escalation exploit
CVE-2025-13486CRITICAL19 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC6
PoC for CVE-2025-37164
CVE-2025-37164CRITICALunder attack19 Dec 2025
A remote code execution issue exists in HPE OneView.
100RISK
open
GitHub PoC
POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on hands-on exploitation steps, reproducible test cases, and observable impact, helping security researchers and defenders understand the issue and validate fixes.
CVE-2025-33053HIGHunder attack18 Dec 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISK
open
GitHub PoC9
Proof-of-Concept exploit for CVE-2025-14174 (EUVD-2025-203113) - Memory corruption in ANGLE allowing out-of-bounds access and RCE in web browsers. Reliable on iOS/Android/Windows, including patched systems with incomplete fixes.
CVE-2025-14174HIGHunder attack18 Dec 2025
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISK
open
GitHub PoC2
Detection for CVE-2025-37164
CVE-2025-37164CRITICALunder attack18 Dec 2025
A remote code execution issue exists in HPE OneView.
100RISK
open
GitHub PoC2
Cisco is aware of a potential vulnerability.&nbsp; Cisco is currently investigating and&nbsp;will update these details as appropriate&nbsp;as more information becomes available.
CVE-2025-20393CRITICALunder attack18 Dec 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open
GitHub PoC
KingHacker353/CVE-2025-20393
CVE-2025-20393CRITICALunder attack18 Dec 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open
GitHub PoC22
Script to detect CVE-2025-20393 for Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
CVE-2025-20393CRITICALunder attack18 Dec 2025
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open
GitHub PoC
Lightweight Go toolkit plus a Dockerized Next.js lab to explore and triage CVE-2025-55182.
CVE-2025-55182CRITICALunder attackransomware18 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC4
React2Shell (CVE-2025-66478): A Python-based Proof of Concept for Critical Remote Code Execution (RCE) in Next.js Server Components. Features an interactive CLI, custom payload injection, and cleaner output formatting. For educational research only.
CVE-2025-55182CRITICALunder attackransomware18 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Bitrix24 <= 25.100.300 (Translate Module) Remote Code Execution Vulnerability
CVE-2025-67886MEDIUM18 Dec 2025
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translat
33RISK
open
GitHub PoC
rashedhasan090/cve-2025-55182-mitigator
CVE-2025-55182CRITICALunder attackransomware18 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
React2Shell Vulnerability Verification Script (React2Shell also known as CVE-2025-55182).
CVE-2025-55182CRITICALunder attackransomware18 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
previouspage 153 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.