Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
75,589 exploits
GitHub PoC
donmedfor/CVE-2015-3306
CVE-2015-330623 Aug 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC1
POC exploit for CVE-2025-33053 (external control of file execution path in URL file)
CVE-2025-33053HIGHunder attack23 Aug 2025
Internet Shortcut Files Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Este repositório contém um script de prova de conceito (PoC) que demonstra uma vulnerabilidade crítica encontrada no plugin Simple File List para WordPress.
CVE-2020-36847CRITICAL23 Aug 2025
Simple File List < 4.2.3 - Remote Code Execution
68RISK
open
GitHub PoC
A PHP CGI Vulnerability Scanner for CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware23 Aug 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Telerik CVE-2019-18935 Vulnerability Scanner
CVE-2019-18935CRITICALunder attackransomware22 Aug 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC
The exploit code for CVE-2025-43300.
CVE-2025-43300CRITICALunder attack22 Aug 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack22 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
Explotación vulnerabilidad Dirty COW (CVE-2016-5195) en Ubuntu 16.04.1.
CVE-2016-5195HIGHunder attack22 Aug 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC1
Kryptoenix/CVE-2025-47987_PoC
CVE-2025-47987HIGH22 Aug 2025
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC1
Some poorly crafted exploit scripts
CVE-2025-24893CRITICALunder attack22 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC1
Fix for undefined method each in Metasploit’s bailiwicked_domain.rb (CVE-2008-1447 DNS cache poisoning module)
CVE-2008-144722 Aug 2025
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISK
open
GitHub PoC2
PoC exploit for Below privilege escalation (CVE-2025-27591) allowing local root access via symlink manipulation in world-writable log directory.
CVE-2025-27519CRITICAL22 Aug 2025
Cognita Arbitrary File Write
48RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack22 Aug 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
0xr2r/CVE-2024-4367
CVE-2024-4367MEDIUM22 Aug 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
VulnCheck XDB
initial-access
CVE-2015-835121 Aug 2025
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
VulnCheck XDB
initial-access
CVE-2023-41892CRITICAL21 Aug 2025
Craft CMS Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-3721MEDIUM21 Aug 2025
TBK DVR-4104/DVR-4216 os command injection
55RISK
open
GitHub PoC
Exploit code for CVE-2015-8351
CVE-2015-835121 Aug 2025
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RISK
open
GitHub PoC1
CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool
CVE-2023-35078CRITICALunder attackransomware21 Aug 2025
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC
Customized this for my own use
CVE-2023-41892CRITICAL21 Aug 2025
Craft CMS Remote Code Execution vulnerability
85RISK
open
GitHub PoC
This PoC is for authorized study and testing. CVE-2025-8088 is actively exploited, and misuse may violate laws or cause harm. Update to WinRAR 7.13+ to avoid suspicious RARs.
CVE-2025-8088HIGHunder attack21 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
Ianthinus/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware20 Aug 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC3
A Windows GUI tool demonstrating a proof-of-concept archive traversal technique related to CVE-2025-8088 using WinRAR’s CLI. Allows building crafted RAR files with payload + decoy files through an easy modern interface. For educational and security-research purposes only.
CVE-2025-8088HIGHunder attack20 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
shoucheng3/apache__flink_CVE-2020-17519_1-11-2
CVE-2020-17519CRITICALunder attack20 Aug 2025
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC
replicatorbot/CVE-2025-48384
CVE-2025-48384HIGHunder attack20 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
replicatorbot/CVE-2025-48384-POC
CVE-2025-48384HIGHunder attack20 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC1
The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The assessment will focus on exploiting a specific, real-world vulnerability (CVE-2021-29447) to achieve initial access.
CVE-2021-29447HIGH20 Aug 2025
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC
harshitvarma05/CVE-2025-31324-Exploits
CVE-2025-31324CRITICALunder attackransomware20 Aug 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
VulnCheck XDB
client-side
CVE-2025-54782CRITICAL20 Aug 2025
@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
75RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack20 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
previouspage 211 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.