Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,526cataloged exploits
34,478CVEs with public exploitation
24,695lab-tested
75,526 exploits
GitHub PoC
A XXE payload generator
CVE-2021-29447HIGH31 Oct 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC1
adrianmafandy/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware31 Oct 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Mahfujurjust/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware31 Oct 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Fast, socket-level scanner for detecting CVE-2022-22536 in SAP ICM or Web Dispatcher instances. Performs request smuggling tests with a crafted MPI-desync payload. Supports batch scanning IP:PORT targets via plain text files.
CVE-2022-22536CRITICALunder attack31 Oct 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware31 Oct 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack31 Oct 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-49844CRITICAL31 Oct 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
VulnCheck XDB
client-side
CVE-2025-64095CRITICAL31 Oct 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
75RISK
open
VulnCheck XDB
infoleak
CVE-2022-22536CRITICALunder attack31 Oct 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open
Exploit-DB
Flowise 3.0.4 - Remote Code Execution (RCE)
CVE-2025-59528CRITICALwebappsmultiple31 Oct 2025
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack31 Oct 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC25
Proof-of-concept for CVE-2025-49844
CVE-2025-49844CRITICAL31 Oct 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
GitHub PoC1
shiro 路径穿越
CVE-2010-386331 Oct 2025
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the
35RISK
open
VulnCheck XDB
initial-access
CVE-2024-50603CRITICALunder attack30 Oct 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza
100RISK
open
Metasploit600
WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE
CVE-2025-8489CRITICAL30 Oct 2025
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
43RISK
open
GitHub PoC1
WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload
CVE-2025-6440CRITICAL30 Oct 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL30 Oct 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack29 Oct 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
local
CVE-2021-31955MEDIUMunder attack29 Oct 2025
Windows Kernel Information Disclosure Vulnerability
85RISK
open
GitHub PoC2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
CVE-2021-31955MEDIUMunder attack29 Oct 2025
Windows Kernel Information Disclosure Vulnerability
85RISK
open
GitHub PoC
TranDongA3/Simulation_CVE-2024-46256
CVE-2024-46256CRITICAL29 Oct 2025
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISK
open
GitHub PoC2
A combined POC for CVE-2021-31955, CVE-2015-4077, and CVE-2015-5736
CVE-2015-407729 Oct 2025
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RISK
open
Exploit-DB
Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927webappsmultiple29 Oct 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISK
open
Metasploit600
Taiga tribe_gig authenticated unserialize remote code execution
CVE-2025-62368CRITICAL28 Oct 2025
Taiga Authenticated Remote Code Execution
43RISK
open
GitHub PoC
A powerful and reliable exploit tool for Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013. This tool provides remote code execution capabilities on vulnerable Apache 2.4.49 and 2.4.50 servers.
CVE-2021-42013CRITICALunder attackransomware28 Oct 2025
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
Zohaibkhan1472/cve-2023-6019
CVE-2023-6019CRITICAL28 Oct 2025
Ray Command Injection in cpu_profile Parameter
85RISK
open
GitHub PoC
ict519 assignment
CVE-2023-38831HIGHunder attackransomware28 Oct 2025
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
Demo of CVE-2021-44228 Log4Shell.
CVE-2021-44228CRITICALunder attackransomware28 Oct 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware28 Oct 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
Exploit for Remote Code Execution in ColdFusion 2021 (CVE-2023-26360)
CVE-2023-26360HIGHunder attack28 Oct 2025
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RISK
open
previouspage 189 / 2,518next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.