Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
75,652 exploits
GitHub PoC
Scouserr/cve-2022-0847-poc-dockerimage
CVE-2022-0847HIGHunder attack07 Aug 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
Bash POC script for RCE vulnerability in XWiki Platform
CVE-2025-24893CRITICALunder attack07 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC1
CVE-2025-24893 is a critical unauthenticated remote code execution (RCE) vulnerability in XWiki, a popular open-source enterprise wiki platform.
CVE-2025-24893CRITICALunder attack07 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack07 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack07 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack07 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30406CRITICALunder attack07 Aug 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
GitHub PoC5
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
CVE-2025-34152CRITICAL07 Aug 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISK
open
GitHub PoC1
PoC to inject a command via the DEVICE_PING endpoint
CVE-2025-7769HIGH07 Aug 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
46RISK
open
Metasploit600
Grav CMS Admin Direct Install Authenticated Plugin Upload RCE
CVE-2025-50286HIGH07 Aug 2025
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack07 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-34152CRITICAL07 Aug 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware07 Aug 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-53770CRITICALunder attackransomware07 Aug 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601
CVE-2021-3544806 Aug 2025
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALunder attackransomware06 Aug 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC1
Automated scanner + exploit for CVE-2025-24813
CVE-2025-24813CRITICALunder attack06 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC1
🔒 Spring4Shell Firewall Defense — Cybersecurity Incident Simulation This project is part of a Cybersecurity Job Simulation I completed in August 2025 through Forage. It focuses on detecting, analyzing, and mitigating a simulated real-world cyberattack involving the Spring4Shell (CVE-2022-22965) vulnerability
CVE-2022-22965CRITICALunder attack06 Aug 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC3
PoC for CVE-2025-24893
CVE-2025-24893CRITICALunder attack06 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC1
Simulated PoC for CVE-2025-54253: Adobe AEM OGNL Injection Vulnerability
CVE-2025-54253CRITICALunder attack06 Aug 2025
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISK
open
GitHub PoC
esmwaSpyware/DoS-PoC-for-CVE-2020-0796-SMBGhost-
CVE-2020-0796CRITICALunder attackransomware06 Aug 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack06 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack06 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware05 Aug 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack05 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack05 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack05 Aug 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack05 Aug 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2023-22809HIGH05 Aug 2025
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack05 Aug 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
previouspage 219 / 2,522next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.