Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
75,589 exploits
GitHub PoC5
yukinime/CVE-2025-6934
CVE-2025-6934CRITICAL27 Aug 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack27 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack27 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack27 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.
CVE-2007-244727 Aug 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
local
CVE-2018-19323CRITICALunder attackransomware27 Aug 2025
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
78RISK
open
GitHub PoC
An exploitation framework for CVE-2018-19323 - GIGABYTE GDrv privilege escalation vulnerability with multi-architecture support and framework integration
CVE-2018-19323CRITICALunder attackransomware27 Aug 2025
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
78RISK
open
GitHub PoC
te0rwx/CVE-2025-32433-Detection
CVE-2025-32433CRITICALunder attack27 Aug 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC5
walidpyh/CVE-2025-8088
CVE-2025-8088HIGHunder attack27 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC8
A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.
CVE-2025-8088HIGHunder attack27 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC10
Winrar CVE exploitation before 7.13 using multiple ADS streams on a single file (Custom PDF implementation)
CVE-2025-8088HIGHunder attack27 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
hacieda/CVE-2025-32463
CVE-2025-32463CRITICALunder attack27 Aug 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack27 Aug 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC3
用于CVE-2025-32463 sudo_chwoot的权限提升POC,适配了有gcc编译环境和无gcc编译环境的两种情况,下载运行即可一把梭哈
CVE-2025-32463CRITICALunder attack27 Aug 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-34030CRITICAL26 Aug 2025
sar2html OS Command Injection
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
a1ex-var1amov/ctf-cve-2019-11043
CVE-2019-11043HIGHunder attackransomware26 Aug 2025
Underflow in PHP-FPM can lead to RCE
100RISK
open
Exploit-DB
Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
CVE-2025-6082MEDIUMwebappsmultiple26 Aug 2025
Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure
33RISK
open
GitHub PoC1
Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell.
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC1
DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC
CVE-2025-8088HIGHunder attack26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC12
An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist.
CVE-2025-8088HIGHunder attack26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC1
POWERSHEL script to check if your device is affected or no
CVE-2025-8088HIGHunder attack26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
Exploit-DB
GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)
CVE-2025-26264HIGHremotewindows26 Aug 2025
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RISK
open
Exploit-DB
StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
CVE-2025-7441CRITICALwebappsmultiple26 Aug 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC
PoC for CVE-2025-34030 sar2html 'plot' parameter RCE
CVE-2025-34030CRITICAL26 Aug 2025
sar2html OS Command Injection
75RISK
open
GitHub PoC1
Real4XoR/CVE-2019-6693
CVE-2019-6693MEDIUMunder attackransomware26 Aug 2025
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
Exploit-DB
GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
CVE-2025-26263MEDIUMlocalwindows26 Aug 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attack26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
previouspage 209 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.