Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,432 exploits
GitHub PoC
Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS), and enterprise mitigation guidance.
CVE-2021-44228CRITICALunder attackransomware18 Nov 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Hands‑on analysis of CVE‑2025‑62215, a Windows Kernel race condition exploited in the wild. Demonstrates privilege escalation to SYSTEM, detection scripts, and patch validation strategies for enterprise defenders and red teamers.
CVE-2025-62215HIGHunder attack18 Nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
0xr2r/CVE-2025-64095
CVE-2025-64095CRITICAL18 Nov 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
75RISK
open
GitHub PoC19
This PoC demonstrates a race condition in the Windows kernel leading to a double-free vulnerability, allowing local privilege escalation to SYSTEM. The exploit uses multithreaded handle manipulation and heap spraying to trigger the flaw under controlled conditions.
CVE-2025-62215HIGHunder attack18 Nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack18 Nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER
CVE-2022-0543CRITICALunder attack18 Nov 2025
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack17 Nov 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
local
CVE-2019-13272HIGHunder attack17 Nov 2025
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC2
This Python PoC script detects the Heartbleed vulnerability (CVE-2014-0160) by performing a TLS handshake with heartbeat extension and sending a crafted heartbeat request. It parses responses to identify leaked memory, helping assess server susceptibility to this critical OpenSSL flaw.
CVE-2014-0160HIGHunder attack17 Nov 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-31199CRITICALunder attackransomware17 Nov 2025
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting bot
90RISK
open
GitHub PoC
FortiWeb Unauthenticated RCE via Path Traversal & CGI Auth Bypass
CVE-2025-64446CRITICALunder attack17 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
kautilyagupt/CVE-2024-26169-Detail-1
CVE-2024-26169HIGHunder attackransomware17 Nov 2025
Windows Error Reporting Service Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
developerfred/CVE-2022-31199
CVE-2022-31199CRITICALunder attackransomware17 Nov 2025
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting bot
90RISK
open
GitHub PoC31
A scanner for the FortiNet vulnerability CVE-2025-64446
CVE-2025-64446CRITICALunder attack17 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-21587CRITICALunder attackransomware17 Nov 2025
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open
GitHub PoC
letsr00t/CVE-2019-13272
CVE-2019-13272HIGHunder attack17 Nov 2025
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC
This lab simulates CVE-2019-9193 - PostgreSQL COPY FROM PROGRAM RCE
CVE-2019-919317 Nov 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack17 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
CVE-2015-3306 - ProFTPD - RCE Home Lab setup (Docker) easy to use for Red Teaming or Penetration Testing
CVE-2015-330617 Nov 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack17 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
Vulnerability Found on Squid Proxy.
CVE-2025-54574CRITICAL17 Nov 2025
Squid's URN Handling can lead to Buffer Overflow
53RISK
open
GitHub PoC
CVE-2017-12615 Tomcat: Remote Code Execution via JSP Upload Home Lab for Red Teaming, Penetration Testing
CVE-2017-12615HIGHunder attackransomware17 Nov 2025
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC
This exploit demonstrates a **path traversal vulnerability** in Xibo CMS (CVE-2023-33177) that allows remote code execution through malicious layout imports.
CVE-2023-33177HIGH17 Nov 2025
Xibo CMS vulnerable to Remote Code Execution through Zip Slip
41RISK
open
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
CVE-2025-11700HIGH17 Nov 2025
N-central Multiple XXE Injection Vulnerabilities
68RISK
open
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
CVE-2025-9316MEDIUM17 Nov 2025
N-central unauthenticated sessionID generation
60RISK
open
GitHub PoC
CVE-2025-33073
CVE-2025-33073HIGHunder attack17 Nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC3
CVE-2025-64446 - A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-64446CRITICALunder attack17 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.
CVE-2025-49113CRITICALunder attack17 Nov 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and mitigation steps.
CVE-2025-32463CRITICALunder attack16 Nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
placeholder for CitrixBleed 2.0 CVE-2025-5777
CVE-2025-5777CRITICALunder attackransomware16 Nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
previouspage 182 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.