Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,017 exploits
GitHub PoC1
Proof‑of‑concept for CVE‑2024‑58258, a SugarCRM (<13.0.4 / <14.0.1) flaw where user input is parsed as LESS in /css/preview, allowing unauthenticated SSRF or local file access.
CVE-2024-58258HIGH21 Nov 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RISK
open
GitHub PoC2
A self-contained testbed for Django CVE-2025-64459. Demonstrates QuerySet.filter() parameter injection via dictionary expansion using Docker.
CVE-2025-64459CRITICAL21 Nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open
GitHub PoC4
Oracle Identity Manager 远程代码执行漏洞CVE-2025-61757
CVE-2025-61757CRITICALunder attack21 Nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISK
open
GitHub PoC1
Proof‑of‑concept description for CVE‑2025‑47916, a Remote Code Execution vulnerability affecting Invision Community 5.0.0–5.0.6 via unsafe template processing in the "customCss()" method.
CVE-2025-47916CRITICAL21 Nov 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISK
open
GitHub PoC
Sorumluluk Reddi Kendi sorumluluğunuzda kullanın, size ait olmayan veya tarama izninizin olmadığı altyapılarda gerçekleştireceğiniz yasa dışı faaliyetlerden sorumlu olmayacağım.
CVE-2025-61882CRITICALunder attackransomware21 Nov 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack21 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47916CRITICAL21 Nov 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack21 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC1
Adel-kaka-dz/cve-2025-59287
CVE-2025-59287CRITICALunder attack21 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Hands-on security lab demonstrating CVE-2023-22515 — Atlassian Confluence Authentication Bypass using a simulated vulnerable environment.
CVE-2023-22515CRITICALunder attackransomware21 Nov 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC1
Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table, three hunts (KQL/SPL/Sigma), first-4-hours comms, sample data, and figures. Built for fast triage; no org data; SharePoint Online out of scope.
CVE-2025-53770CRITICALunder attackransomware21 Nov 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Fully automated Confluence RCE exploit (CVE-2023-22527 + OGNL injection) 100% from scratch • Python • 2025
CVE-2023-22527CRITICALunder attackransomware21 Nov 2025
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISK
open
GitHub PoC1
SAP RCE auto-chain (CVE-2024-22127 + DIAG)
CVE-2024-22127CRITICAL21 Nov 2025
Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
48RISK
open
GitHub PoC
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
CVE-2025-13390CRITICAL20 Nov 2025
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RISK
open
GitHub PoC
thepiyushkumarshukla/CVE-2022-24707_AnukoTimeTracker_Version-1.20.0_POC
CVE-2022-24707HIGH20 Nov 2025
SQL injection in anuko timetracker
41RISK
open
GitHub PoC
On February 13th, 2024, Microsoft announced a Microsoft Outlook RCE & credential leak vulnerability with the assigned CVE of CVE-2024-21413 (Moniker Link). Haifei Li of Check Point Research is credited with discovering the vulnerability. The vulnerability bypasses Outlook's security mechanisms when handing a specific type of hyperlink .
CVE-2024-21413CRITICALunder attack20 Nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
anelya0333/Exploiting-CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware20 Nov 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware20 Nov 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack20 Nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack20 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)
CVE-2025-12735CRITICAL20 Nov 2025
CVE-2025-12735
48RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH20 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC1
Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework
CVE-2022-22965CRITICALunder attack20 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-13390CRITICAL20 Nov 2025
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RISK
open
GitHub PoC
Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action
CVE-2025-13374CRITICAL20 Nov 2025
Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action
48RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-61757CRITICALunder attack20 Nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISK
open
GitHub PoC
lastvocher/7zip-CVE-2025-11001
CVE-2025-11001HIGH20 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC3
A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in Langflow versions ≤ 1.3.0.
CVE-2025-3248CRITICALunder attackransomware20 Nov 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHunder attackransomware19 Nov 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
MonstaFTP Unauthenticated File Upload
CVE-2025-34299CRITICAL19 Nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
previouspage 174 / 2,501next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.