Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
75,589 exploits
GitHub PoC1
jsnv-dev/CVE-2024-51568---CyberPanel-Command-Injection-Nuclei-Template
CVE-2024-51568CRITICAL02 Sep 2025
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISK
open
GitHub PoC1
a proof of concept of CVE-2024-53677
CVE-2024-53677CRITICAL01 Sep 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack01 Sep 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC6
FreePBX SQL Injection Exploit
CVE-2025-57819CRITICALunder attack01 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC1
Sawtooth Lighthouse Studio存在模板注入漏洞CVE-2025-34300
CVE-2025-34300CRITICAL01 Sep 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISK
open
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware01 Sep 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALunder attack01 Sep 2025
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-1920701 Sep 2025
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISK
open
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALunder attack01 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11357CRITICALunder attackransomware01 Sep 2025
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL01 Sep 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-34300CRITICAL01 Sep 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISK
open
GitHub PoC1
HTML cache poisoning through unsafe reflections
CVE-2025-53693CRITICAL01 Sep 2025
HTML Cache Poisoning through Unsafe Reflections
53RISK
open
VulnCheck XDB
initial-access
CVE-2025-3515HIGH01 Sep 2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RISK
open
GitHub PoC
Detection for CVE-2025-4427 and CVE-2025-4428
CVE-2025-4427MEDIUMunder attack31 Aug 2025
Authentication Bypass
100RISK
open
VulnCheck XDB
local
CVE-2025-7771HIGH31 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
VulnCheck XDB
infoleak
CVE-2024-48307CRITICAL31 Aug 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RISK
open
GitHub PoC1
jeecg-boot getDictItemsByTable接口存在SQL注入漏洞
CVE-2024-48307CRITICAL31 Aug 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack31 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
client-side
CVE-2015-925131 Aug 2025
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RISK
open
GitHub PoC
It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have tweaked the chain from a simple DLL to a full reverse‑shell stack, and what that means for the defenders.
CVE-2025-2776CRITICALunder attack31 Aug 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RISK
open
GitHub PoC18
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
CVE-2025-7771HIGH31 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware31 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Detection for CVE-2025-7775
CVE-2025-7775CRITICALunder attack31 Aug 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISK
open
GitHub PoC
CTF_WRITEUPS/TryHackMe /CVE-2021-41773/
CVE-2021-41773HIGHunder attackransomware31 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC20
Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast
CVE-2025-24813CRITICALunder attack31 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALunder attack30 Aug 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC4
PHPUnit CVE-2017-9841 Scanner in Go clean and fire.
CVE-2017-9841CRITICALunder attack30 Aug 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALunder attackransomware30 Aug 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
Aaqilyousuf/CVE-2025-7775-vulnerable-lab
CVE-2025-7775CRITICALunder attack30 Aug 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISK
open
previouspage 207 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.