Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,526 exploits
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware05 Nov 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14883HIGHunder attack05 Nov 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC1
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
CVE-2025-9209CRITICAL05 Nov 2025
RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
63RISK
open
GitHub PoC
Billing CTF Machine_CVE-2023-30258_Remote Code Execution
CVE-2023-30258CRITICAL05 Nov 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-53690CRITICALunder attack05 Nov 2025
Sitecore Products ViewState Deserialization Vulnerability
90RISK
open
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALunder attack05 Nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISK
open
VulnCheck XDB
initial-access
CVE-2024-5932CRITICAL04 Nov 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALunder attack04 Nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISK
open
Metasploit600
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
CVE-2025-11749CRITICAL04 Nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISK
open
GitHub PoC8
A vulnerability in fiberhome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID
CVE-2025-63353CRITICAL04 Nov 2025
A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s
48RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack04 Nov 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
PoC for CVE-2024-5932.
CVE-2024-5932CRITICAL04 Nov 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
GitHub PoC10
Breaking down CVE-2025-54253 — an Adobe AEM-Forms exploit path from XXE to full remote code execution and its real-world impact.
CVE-2025-54253CRITICALunder attack04 Nov 2025
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISK
open
GitHub PoC4
CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits and mitigation strategies.
CVE-2025-11953CRITICALunder attack04 Nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack03 Nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC1
XWiki Unauthenticated RCE Exploit for Reverse Shell
CVE-2025-24893CRITICALunder attack03 Nov 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack03 Nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack03 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Exploit for CVE-2025-2011
CVE-2025-2011HIGH02 Nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack02 Nov 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC1
My view on IngressNightmare vulnerability (CVE-2025-1974)
CVE-2025-1974CRITICAL02 Nov 2025
ingress-nginx admission controller RCE escalation
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-2011HIGH02 Nov 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open
GitHub PoC1
This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.
CVE-2015-330602 Nov 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC1
A Proof of Concept (PoC) exploit for CVE-2015-1328
CVE-2015-132801 Nov 2025
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC
CVE-2024-9047
CVE-2024-9047CRITICAL01 Nov 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack01 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Exploit for CVE-2021-3560 Polkit Local Privilege Escalation Vulnerability
CVE-2021-3560HIGHunder attack01 Nov 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2015-132801 Nov 2025
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
VulnCheck XDB
infoleak
CVE-2024-9047CRITICAL01 Nov 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack01 Nov 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
previouspage 188 / 2,518next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.