Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,526 exploits
GitHub PoC12
CVE-2025-6554
CVE-2025-6554HIGHunder attack09 Nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
GitHub PoC
A proof of concept for CVE-2025-24054/CVE-2025-24071
CVE-2025-24054MEDIUMunder attack09 Nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
Metasploit600
FreePBX filestore authenticated command injection
CVE-2025-64328HIGHunder attack08 Nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RISK
open
VulnCheck XDB
client-side
CVE-2025-21042HIGHunder attack08 Nov 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
83RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack08 Nov 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
l1nuxkid/CVE-2025-32433-exploit
CVE-2025-32433CRITICALunder attack08 Nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
letsr00t/-CVE-2019-18634-sudo-pwfeedback
CVE-2019-1863408 Nov 2025
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack08 Nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC9
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
CVE-2025-11749CRITICAL08 Nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-11749CRITICAL08 Nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISK
open
GitHub PoC1
Emergency Chrome update information and tools for CVE-2023-7024 and other critical vulnerabilities
CVE-2023-7024HIGHunder attack07 Nov 2025
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
71RISK
open
GitHub PoC1
Emergency Chrome update information and tools for CVE-2023-7024 and other critical vulnerabilities
CVE-2023-7024HIGHunder attack07 Nov 2025
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit
71RISK
open
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALunder attackransomware07 Nov 2025
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
GitHub PoC10
Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.
CVE-2024-9680CRITICALunder attackransomware07 Nov 2025
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli
83RISK
open
GitHub PoC
Tomcat - PUT Method
CVE-2017-12615HIGHunder attackransomware07 Nov 2025
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
Metasploit600
Monsta FTP downloadFile Remote Code Execution
CVE-2025-34299CRITICAL07 Nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
VulnCheck XDB
client-side
CVE-2025-9491MEDIUM07 Nov 2025
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability
45RISK
open
VulnCheck XDB
client-side
CVE-2025-64095CRITICAL06 Nov 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-54782CRITICAL06 Nov 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-54236CRITICALunder attack06 Nov 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
GitHub PoC2
This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients when handling SMB/moniker-style links embedded in messages. The PoC and experiments documented here were performed in a controlled lab environment on systems.
CVE-2024-21413CRITICALunder attack06 Nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
rockmelodies/django_sqli_target_CVE-2025-64459
CVE-2025-64459CRITICAL06 Nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open
GitHub PoC5
demo CVE-2019-2215 (Bad Binder) for Android Q
CVE-2019-2215HIGHunder attack06 Nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack06 Nov 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack06 Nov 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack06 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-21587CRITICALunder attackransomware06 Nov 2025
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RISK
open
GitHub PoC
CVE-2025-54782
CVE-2025-54782CRITICAL06 Nov 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISK
open
GitHub PoC
A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).
CVE-2024-4040CRITICALunder attack05 Nov 2025
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC1
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
CVE-2025-9209CRITICAL05 Nov 2025
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
63RISK
open
previouspage 187 / 2,518next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.