Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
75,589 exploits
Exploit-DB
Tenda AC20 16.03.08.12 - Command Injection
CVE-2025-9090MEDIUMremotemultiple18 Aug 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RISK
open
Exploit-DB
PHPMyAdmin 3.0 - Bruteforce Login Bypass
CVE-2015-6830remotephp18 Aug 2025
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allo
23RISK
open
GitHub PoC
shoucheng3/keycloak__keycloak_CVE-2022-3782_20-0-1
CVE-2022-3782CRITICAL18 Aug 2025
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs
48RISK
open
GitHub PoC3
This is an improved version of the CVE-2025-49132 proof of concept exploit.
CVE-2025-49132CRITICAL18 Aug 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC2
Proof of concept for CVE-2020-36708
CVE-2020-36708CRITICAL18 Aug 2025
Epsilon Framework Themes (Various Versions) - Function Injection
75RISK
open
GitHub PoC5
CVE PoC
CVE-2013-3900MEDIUMunder attack18 Aug 2025
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
CVE-2025-4334CRITICAL18 Aug 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISK
open
VulnCheck XDB
infoleak
CVE-2020-36708CRITICAL18 Aug 2025
Epsilon Framework Themes (Various Versions) - Function Injection
75RISK
open
GitHub PoC
chan-068/CVE-2024-0520_try
CVE-2024-0520CRITICAL18 Aug 2025
Remote Code Execution due to Full Controlled File Write in mlflow/mlflow
48RISK
open
Exploit-DB
BigAnt Office Messenger 5.6.06 - SQL Injection
CVE-2024-54761MEDIUMwebappsmultiple18 Aug 2025
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RISK
open
Exploit-DB
RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
CVE-2024-28623MEDIUMwebappsmultiple18 Aug 2025
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RISK
open
GitHub PoC1
harutomo-jp/CVE-2024-28397-RCE
CVE-2024-28397MEDIUM18 Aug 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC
CyberQuestor-infosec/CVE-2025-49113-Roundcube_1.6.10
CVE-2025-49113CRITICALunder attack18 Aug 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
Exploit-DB
Lantronix Provisioning Manager 7.10.3 - XML External Entity Injection (XXE)
CVE-2025-7766HIGHwebappsmultiple18 Aug 2025
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RISK
open
VulnCheck XDB
initial-access
CVE-2014-873918 Aug 2025
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL18 Aug 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
local
CVE-2025-7771HIGH18 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC
shoucheng3/spring-projects__spring-security_CVE-2011-2732_2-0-6-RELEASE
CVE-2011-273217 Aug 2025
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RISK
open
GitHub PoC
Demo of CVE-2025-29927 for secure programming class
CVE-2025-29927CRITICAL17 Aug 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC3
PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool
CVE-2025-32778CRITICAL17 Aug 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISK
open
GitHub PoC
CVE-2019-12185 - eLabFTW 1.8.5 Python3 Exploit POC
CVE-2019-1218517 Aug 2025
eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may
28RISK
open
GitHub PoC
shoucheng3/apache__rocketmq_CVE-2023-33246_5-1-0
CVE-2023-33246CRITICALunder attack17 Aug 2025
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RISK
open
GitHub PoC1
Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)
CVE-2025-9090MEDIUM17 Aug 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RISK
open
GitHub PoC
Proof-of-Concept exploit script for Xdebug 2.5.5 and earlier versions (CVE-2015-10141).
CVE-2015-10141CRITICAL17 Aug 2025
Xdebug Remote Debugger Unauthenticated OS Command Execution
63RISK
open
GitHub PoC
shoucheng3/spring-cloud__spring-cloud-config_CVE-2020-5410_2-1-8-RELEASE
CVE-2020-5410HIGHunder attack17 Aug 2025
Directory Traversal with spring-cloud-config-server
100RISK
open
GitHub PoC2
Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)
CVE-2025-8088HIGHunder attack17 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC21
Detection for CVE-2025-8875 & CVE-2025-8876
CVE-2025-8875CRITICALunder attack17 Aug 2025
Insecure Deserialization Vulnerability
78RISK
open
VulnCheck XDB
initial-access
CVE-2025-32778CRITICAL17 Aug 2025
Web-Check allows command Injection via Unvalidated URL in Screenshot API
68RISK
open
GitHub PoC5
This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access dangerous classes like subprocess.Popen, leading to arbitrary command execution.
CVE-2024-28397MEDIUM17 Aug 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC1
Ash1996x/CVE-2025-50154-Aggressor-Script
CVE-2025-50154MEDIUM16 Aug 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
previouspage 213 / 2,520next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.