Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
75,589 exploits
VulnCheck XDB
client-side
CVE-2025-4123HIGH12 Sep 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
GitHub PoC4
Ash1996x/CVE-2025-54914-PoC
CVE-2025-54914CRITICAL12 Sep 2025
Azure Networking Elevation of Privilege Vulnerability
48RISK
open
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALunder attack12 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC
exploit of CVE-2022-0847 which directly remove password of the root account
CVE-2022-0847HIGHunder attack11 Sep 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC1
In-depth study of CVE-2019-18935 affecting Telerik UI for ASP.NET AJAX. Covers .NET deserialization vulnerability, RadAsyncUpload handler, gadget chains, mixed-mode assembly exploitation, and mitigation strategies.
CVE-2019-18935CRITICALunder attackransomware11 Sep 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
Detection for CVE-2025-42944
CVE-2025-42944CRITICAL11 Sep 2025
Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)
48RISK
open
GitHub PoC1
For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.
CVE-2021-4034HIGHunder attack11 Sep 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demos
CVE-2017-5638CRITICALunder attackransomware11 Sep 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware11 Sep 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL11 Sep 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack11 Sep 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
This repository contains **research and analysis** related to CVE-2025-29927. It demonstrates safe, controlled testing approaches for a path traversal/middleware misconfiguration vulnerability in web applications.
CVE-2025-29927CRITICAL11 Sep 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
local
CVE-2022-0847HIGHunder attack11 Sep 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware10 Sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC
Nexus Repository 3 Path Traversal (CVE-2024-4956)
CVE-2024-4956HIGH10 Sep 2025
Nexus Repository 3 - Path Traversal
61RISK
open
VulnCheck XDB
local
CVE-2025-42957CRITICAL10 Sep 2025
Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
48RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware10 Sep 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC4
CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full control. The article explains the vulnerability, threat model, provides minimal exploit ABAP code, and lists patching & monitoring steps to secure the system
CVE-2025-42957CRITICAL10 Sep 2025
Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
48RISK
open
GitHub PoC2
PoC CVE-2025-31161 - Authentication Bypass CrushFTP
CVE-2025-31161CRITICALunder attackransomware10 Sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack10 Sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
CVE-2025-24893 RCE exploit for XWiki with reverse shell capability
CVE-2025-24893CRITICALunder attack10 Sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack10 Sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
Zuack55/Roundcube-1.6.10-Post-Auth-RCE-CVE-2025-49113-
CVE-2025-49113CRITICALunder attack10 Sep 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
Linux privilege escalation using Dirty COW exploit (CVE-2016-5195).
CVE-2016-5195HIGHunder attack10 Sep 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
To check for vulnerability CVE-2019-13272
CVE-2019-13272HIGHunder attack10 Sep 2025
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RISK
open
GitHub PoC1
Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and fail2ban evasion techniques. Professional-grade security testing framework for authorized penetration testing engagements.
CVE-2018-15473MEDIUM10 Sep 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC
Jenkins CLI arbitrary file read (CVE-2024-23897)
CVE-2024-23897CRITICALunder attackransomware10 Sep 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
This is a tiny lab that simulates the core idea reported for CVE-2025-54236 (“SessionReaper”)
CVE-2025-54236CRITICALunder attack10 Sep 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
GitHub PoC
This repository contains the corrected code for CVE: 2019-9053
CVE-2019-905309 Sep 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
Log4Shell CVE-2021-44228 PoC
CVE-2021-44228CRITICALunder attackransomware09 Sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
previouspage 203 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.