Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,526 exploits
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack15 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
Detection, Exploit and Mitigation for CVE 2023 46604.
CVE-2023-46604CRITICALunder attackransomware15 Nov 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHunder attack15 Nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC2
Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved Python3 version, usage instructions, and lab testing reference.
CVE-2019-905315 Nov 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC13
soltanali0/CVE-2025-64446-Exploit
CVE-2025-64446CRITICALunder attack15 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC1
CVE-2025-64328 FreePBX Authenticated Command Injection in the framework module.
CVE-2025-64328HIGHunder attack15 Nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RISK
open
GitHub PoC67
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
CVE-2025-33073HIGHunder attack14 Nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC32
CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploited as a zero-day.
CVE-2025-62215HIGHunder attack14 Nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC13
sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-11700HIGH14 Nov 2025
N-central Multiple XXE Injection Vulnerabilities
68RISK
open
VulnCheck XDB
client-side
CVE-2025-33073HIGHunder attack14 Nov 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC7
# CVE-2025-64446 PoC - FortiWeb Path Traversal Proof of Concept para la vulnerabilidad de path traversal en Fortinet FortiWeb que permite ejecución remota de comandos. Incluye herramienta de detección para fines educativos. **⚠️ SOLO USO EDUCATIVO - NO PARA EXPLOTACIÓN ⚠️**
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC1
PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version, health, and database info. For security research and defensive validation only.
CVE-2025-64513CRITICAL14 Nov 2025
Milvus Proxy has Critical Authentication Bypass Vulnerability
48RISK
open
Metasploit300
Fortinet FortiWeb create new local admin
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
local
CVE-2025-62215HIGHunder attack14 Nov 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-9316MEDIUM14 Nov 2025
N-central unauthenticated sessionID generation
60RISK
open
GitHub PoC
CVE-2022-22965 proof of concept for CS4239 report
CVE-2022-22965CRITICALunder attack14 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-58034MEDIUMunder attack14 Nov 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack14 Nov 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack13 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack13 Nov 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
local
CVE-2025-7771HIGH13 Nov 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC6
PoC Exploit CVE-2018-6389
CVE-2018-638913 Nov 2025
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RISK
open
GitHub PoC14
Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel security research
CVE-2025-7771HIGH13 Nov 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC
keyuraghao/CVE-2025-20260
CVE-2025-20260CRITICAL13 Nov 2025
ClamAV PDF Scanning Buffer Overflow Vulnerability
48RISK
open
GitHub PoC
cyhe50/cve-2025-32434-poc
CVE-2025-32434CRITICAL13 Nov 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RISK
open
GitHub PoC
Alex-Acero-Security/CVE-2024-48910-POC
CVE-2024-48910CRITICAL12 Nov 2025
DOMPurify vulnerable to tampering by prototype polution
48RISK
open
previouspage 185 / 2,518next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.