Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,432 exploits
GitHub PoC
anelya0333/Exploiting-CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware20 Nov 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
thepiyushkumarshukla/CVE-2022-24707_AnukoTimeTracker_Version-1.20.0_POC
CVE-2022-24707HIGH20 Nov 2025
SQL injection in anuko timetracker
41RISK
open
GitHub PoC
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
CVE-2025-13390CRITICAL20 Nov 2025
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack20 Nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in Langflow versions ≤ 1.3.0.
CVE-2025-3248CRITICALunder attackransomware20 Nov 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack20 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware20 Nov 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH20 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC1
Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework
CVE-2022-22965CRITICALunder attack20 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC
lastvocher/7zip-CVE-2025-11001
CVE-2025-11001HIGH20 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-61757CRITICALunder attack20 Nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-13390CRITICAL20 Nov 2025
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RISK
open
GitHub PoC
Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)
CVE-2025-12735CRITICAL20 Nov 2025
CVE-2025-12735
48RISK
open
GitHub PoC4
MonstaFTP Unauthenticated File Upload
CVE-2025-34299CRITICAL19 Nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-34299CRITICAL19 Nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
GitHub PoC
PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)
CVE-2022-40684CRITICALunder attackransomware19 Nov 2025
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-15133HIGHunder attack19 Nov 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC
Loaxert/CVE-2018-15133-PoC
CVE-2018-15133HIGHunder attack19 Nov 2025
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RISK
open
GitHub PoC1
A comprehensive Python-based vulnerability scanner for detecting CVE-2021-41773 and CVE-2021-42013 path traversal and remote code execution vulnerabilities in Apache HTTP Server versions 2.4.49 and 2.4.50.
CVE-2021-42013CRITICALunder attackransomware19 Nov 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
Death112233/CVE-2025-64446-
CVE-2025-64446CRITICALunder attack19 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
CVE-2021-1675HIGHunder attackransomware19 Nov 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2021-22205& GitLab CE/EE RCE
CVE-2021-22205CRITICALunder attackransomware19 Nov 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHunder attackransomware19 Nov 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
This repository is a complete walkthrough of the Simple CTF challenge on TryHackMe, featuring Nmap scanning, directory enumeration with Gobuster, exploitation of CVE-2019-9053, SSH access, and privilege escalation via sudo permissions.
CVE-2019-905319 Nov 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
initial-access
CVE-2025-58034MEDIUMunder attack19 Nov 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISK
open
GitHub PoC19
This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading for speed, and honeypot filtering (skips devices with >12 open ports). It's built for red teamers, bug bounty hunters, and security researchers to identify
CVE-2017-7921CRITICALunder attack19 Nov 2025
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER
CVE-2022-0543CRITICALunder attack18 Nov 2025
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
VulnCheck XDB
local
CVE-2025-62215HIGHunder attack18 Nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack18 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
0xr2r/CVE-2025-64095
CVE-2025-64095CRITICAL18 Nov 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
75RISK
open
previouspage 181 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.