Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
80,409 exploits
GitHub PoC
anasrami12/CVE-2025-5548
CVE-2025-5548MEDIUM14 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC7
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC
CVE-2026-3891CRITICAL13 Mar 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
VulnCheck XDB
client-side
CVE-2024-23222HIGHunder attack13 Mar 2026
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.
76RISK
open
GitHub PoC
0xTerror/CVE-2025-6934
CVE-2025-6934CRITICAL13 Mar 2026
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-49844CRITICAL13 Mar 2026
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
GitHub PoC10
Adaptation of Cassowary CVE-2024-23222 for Linux x86_64
CVE-2024-23222HIGHunder attack13 Mar 2026
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.
76RISK
open
GitHub PoC1
CVE-2025-49844
CVE-2025-49844CRITICAL13 Mar 2026
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
GitHub PoC
charlyrr/CVE-2025-5548
CVE-2025-5548MEDIUM13 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
VulnCheck XDB
initial-access
CVE-2024-47176MEDIUM13 Mar 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
GitHub PoC
Entorno y explotación de la vulnerabilidad CVE-2025-5548
CVE-2025-5548MEDIUM13 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
Python PoC for CVE-2025-60787, authenticated OS command injection RCE in motionEye <= 0.43.1b4 via unsanitized image_file_name config
CVE-2025-60787HIGH13 Mar 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware13 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-12057CRITICAL13 Mar 2026
WavePlayer < 3.8.0 - Unauthenticated Arbitrary File Upload
48RISK
open
GitHub PoC1
Proof‑of‑concept Python script demonstrating CVE‑2023‑43208 in Mirth Connect, allowing version checks and command execution on vulnerable instances.
CVE-2023-43208CRITICALunder attackransomware13 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
Research of CVE-2024-3094 vulnerability.
CVE-2024-3094CRITICAL13 Mar 2026
Xz: malicious code in distributed source
70RISK
open
Metasploit600
WordPress Unauthenticated RCE via Pix for WooCommerce plugin
CVE-2026-3891CRITICAL12 Mar 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
CVE-2023-43208CRITICALunder attackransomware12 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
alanschmidt81/CVE-2025-5548
CVE-2025-5548MEDIUM12 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
GitHub PoC
hook repo for cve-2024-32002
CVE-2024-32002CRITICAL12 Mar 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
CVE-2024-32002 Private for Capstone Project CC10
CVE-2024-32002CRITICAL12 Mar 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
LunaLynx12/cve-2023-43208-poc
CVE-2023-43208CRITICALunder attackransomware12 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
Apache HTTP Server (2.4.49) üzerinde CVE-2021-42013 zafiyetini (Path Traversal & RCE) simüle eden Docker tabanlı sızma testi laboratuvarı.
CVE-2021-42013CRITICALunder attackransomware12 Mar 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware12 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware12 Mar 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware12 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware12 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
0x0asif/CVE-2024-21762
CVE-2024-21762CRITICALunder attackransomware12 Mar 2026
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
GitHub PoC
🚀 Complete analysis and exploitation of CVE-2025-5548 (FreeFloat FTP Server 1.0 - NOOP Buffer Overflow) Full methodology: manual tool installation, lab environment setup, fuzzing, offset calculation, bad chars, JMP ESP and working reverse shell exploit.
CVE-2025-5548MEDIUM12 Mar 2026
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
VulnCheck XDB
client-side
CVE-2026-21509HIGHunder attack12 Mar 2026
Microsoft Office Security Feature Bypass Vulnerability
93RISK
open
GitHub PoC
rootxran/CVE-2026-29053
CVE-2026-29053HIGH12 Mar 2026
Ghost Vulnerable to Remote Code Execution via Malicious Themes
56RISK
open
previouspage 177 / 2,681next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.