Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,432 exploits
Exploit-DB
Piwigo 13.6.0 - SQL Injection
CVE-2023-33362CRITICALwebappsphp02 Dec 2025
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
48RISK
open
Exploit-DB
YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
CVE-2022-0088LOWwebappsmultiple02 Dec 2025
Cross-Site Request Forgery (CSRF) in yourls/yourls
28RISK
open
GitHub PoC
boro03/CVE-2021-4034
CVE-2021-4034HIGHunder attack02 Dec 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
This repo contain a PoC I have done when blind analysis the dbutil_2_3.sys driver for vulnerability. This was created by personal analysis without looking at writeups or even know which CVE exist in this driver. All the knowledge I have is that this driver is vulnerable in some way.
CVE-2021-21551HIGHunder attack02 Dec 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
Metasploit600
WordPress ACF Extended Unauthenticated RCE via prepare_form()
CVE-2025-13486CRITICAL02 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC
Vulnerable environment for testing CVE-2021-22941 Nuclei template
CVE-2021-22941CRITICALunder attackransomware02 Dec 2025
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke
90RISK
open
GitHub PoC
towaos/towaos-lab-cve-2020-11023
CVE-2020-11023MEDIUMunder attack02 Dec 2025
Potential XSS vulnerability in jQuery
85RISK
open
VulnCheck XDB
local
CVE-2021-21551HIGHunder attack02 Dec 2025
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RISK
open
Exploit-DB
phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)
CVE-2024-41358MEDIUMwebappsphp02 Dec 2025
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
33RISK
open
Exploit-DB
phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
CVE-2024-41357HIGHwebappsphp02 Dec 2025
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
41RISK
open
GitHub PoC1
Jorge2Rubio/CVE-2019-0232
CVE-2019-023202 Dec 2025
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC
sudlit/CVE-2017-7494
CVE-2017-7494CRITICALunder attackransomware02 Dec 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALunder attackransomware02 Dec 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
Exploit-DB
phpIPAM 1.5.1 - SQL Injection
CVE-2023-1211HIGHwebappsphp02 Dec 2025
SQL Injection in phpipam/phpipam
41RISK
open
VulnCheck XDB
initial-access
CVE-2019-919301 Dec 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
GitHub PoC8
Reverse engineering research and custom firmware for the Allwinner V3-based SJCAM SJ4000 Air, including firmware parsers, an AVIOCTRL client, security research, and the CVE-2026-52656 proof of concept.
CVE-2026-52656CRITICAL01 Dec 2025
An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an a
48RISK
open
GitHub PoC2
Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions: Django 5.1 < 5.1.14, 4.2 < 4.2.26, and 5.2 < 5.2.8. Researcher: Cyberstan (University of Warwick)
CVE-2025-64459CRITICAL01 Dec 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open
GitHub PoC
letsr00t/CVE-2013-2094
CVE-2013-2094HIGHunder attack01 Dec 2025
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISK
open
VulnCheck XDB
infoleak
CVE-2021-2198001 Dec 2025
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n
23RISK
open
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66301HIGH01 Dec 2025
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
36RISK
open
Metasploit600
Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE
CVE-2025-66294HIGH01 Dec 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
36RISK
open
Metasploit600
Eclipse Che machine-exec Unauthenticated RCE
CVE-2025-12548CRITICAL01 Dec 2025
Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333
43RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL01 Dec 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC11
Outlook exploitation
CVE-2024-21413CRITICALunder attack30 Nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3581330 Nov 2025
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL30 Nov 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-21413CRITICALunder attack30 Nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
euxem/Analyse-faille-de-s-curit-CVE-2025-6018-CVE-2025-6019
CVE-2025-6018HIGH30 Nov 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open
GitHub PoC
KylVGoi/cve-2019-1663
CVE-2019-1663CRITICAL29 Nov 2025
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RISK
open
GitHub PoC
xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
CVE-2025-8088HIGHunder attack29 Nov 2025
Path traversal vulnerability in WinRAR
93RISK
open
previouspage 177 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.