Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,432 exploits
GitHub PoC
Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and mitigation steps.
CVE-2025-32463CRITICALunder attack16 Nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack16 Nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-21479HIGHunder attack16 Nov 2025
Incorrect Authorization in Graphics
71RISK
open
GitHub PoC
D-link AX1500 Vulnerability
CVE-2025-60854CRITICAL16 Nov 2025
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during
48RISK
open
GitHub PoC
honeyvig/CVE-2022-0847-DirtyPipe-Exploit
CVE-2022-0847HIGHunder attack16 Nov 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
This repository contains my work for a cybersecurity assignment where I exploited the real-world Log4Shell (CVE-2021-44228) vulnerability inside a safe, controlled virtual machine. The project followed a Capture-the-Flag format with multiple exploitation tasks to retrieve hidden flags.
CVE-2021-44228CRITICALunder attackransomware16 Nov 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC13
Unauthenticated RCE PoC in Microsoft Windows Server Update Service (WSUS) - CVE-2025-59287 & CVE-2023-35317
CVE-2025-59287CRITICALunder attack16 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Detection, Exploit and Mitigation for CVE 2023 46604.
CVE-2023-46604CRITICALunder attackransomware15 Nov 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC1
Twodimensionalitylevelcrossing817/CVE-2025-59287
CVE-2025-59287CRITICALunder attack15 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
CVE-2025-64328 FreePBX Authenticated Command Injection in the framework module.
CVE-2025-64328HIGHunder attack15 Nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RISK
open
GitHub PoC13
soltanali0/CVE-2025-64446-Exploit
CVE-2025-64446CRITICALunder attack15 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC2
Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved Python3 version, usage instructions, and lab testing reference.
CVE-2019-905315 Nov 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack15 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHunder attack15 Nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack15 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-11700HIGH14 Nov 2025
N-central Multiple XXE Injection Vulnerabilities
68RISK
open
VulnCheck XDB
client-side
CVE-2025-33073HIGHunder attack14 Nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC7
# CVE-2025-64446 PoC - FortiWeb Path Traversal Proof of Concept para la vulnerabilidad de path traversal en Fortinet FortiWeb que permite ejecución remota de comandos. Incluye herramienta de detección para fines educativos. **⚠️ SOLO USO EDUCATIVO - NO PARA EXPLOTACIÓN ⚠️**
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC13
sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack14 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-9316MEDIUM14 Nov 2025
N-central unauthenticated sessionID generation
60RISK
open
VulnCheck XDB
local
CVE-2025-62215HIGHunder attack14 Nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC32
CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploited as a zero-day.
CVE-2025-62215HIGHunder attack14 Nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
CVE-2022-22965 proof of concept for CS4239 report
CVE-2022-22965CRITICALunder attack14 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version, health, and database info. For security research and defensive validation only.
CVE-2025-64513CRITICAL14 Nov 2025
Milvus Proxy has Critical Authentication Bypass Vulnerability
48RISK
open
Metasploit300
Fortinet FortiWeb create new local admin
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC67
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
CVE-2025-33073HIGHunder attack14 Nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
previouspage 183 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.