Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,445cataloged exploits
34,432CVEs with public exploitation
24,695lab-tested
75,445 exploits
Metasploit600
FreePBX firmware file upload
CVE-2025-61678HIGH11 Dec 2025
FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter
48RISK
open
Metasploit300
FreePBX Custom Extension SQL Injection
CVE-2025-61675HIGH11 Dec 2025
FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
48RISK
open
GitHub PoC1
CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
Metasploit600
FreePBX endpoint SQLi to RCE
CVE-2025-66039CRITICAL11 Dec 2025
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
63RISK
open
GitHub PoC22
Detection template for CVE-2025-8110
CVE-2025-8110HIGHunder attack11 Dec 2025
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack11 Dec 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53558HIGH11 Dec 2025
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge o
56RISK
open
VulnCheck XDB
initial-access
CVE-2013-015611 Dec 2025
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH11 Dec 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack11 Dec 2025
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-34299CRITICAL11 Dec 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
GitHub PoC
CVE-2025-23061 - Mongoose Command Injection
CVE-2025-23061CRITICAL11 Dec 2025
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NO
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack11 Dec 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection capabilities
CVE-2020-1938CRITICALunder attack11 Dec 2025
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Docker test environment for CVE-2025-34299 - Monsta FTP Pre-Auth RCE vulnerability
CVE-2025-34299CRITICAL11 Dec 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-55182CRITICALunder attackransomware11 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware10 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM10 Dec 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHunder attack10 Dec 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack10 Dec 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMunder attack10 Dec 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
previouspage 160 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.