Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
75,902 exploits
GitHub PoC5
Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE
CVE-2025-25257CRITICALunder attack19 Jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
GitHub PoC
r0otk3r/CVE-2025-41646
CVE-2025-41646CRITICAL19 Jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RISK
open
GitHub PoC
alm6no5/CVE-2024-20767
CVE-2024-20767HIGHunder attack19 Jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
GitHub PoC1
CVE‑2025‑25257 is a critical pre-authentication SQL injection vulnerability affecting Fortinet FortiWeb’s
CVE-2025-25257CRITICALunder attack19 Jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALunder attack19 Jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALunder attack19 Jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware19 Jul 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC7
A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]
CVE-2025-24813CRITICALunder attack19 Jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC8
💥 Python Exploit for CVE-2025-49113 | Roundcube Webmail RCE via PHP Object Injection
CVE-2025-49113CRITICALunder attack19 Jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC2
Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploit sends crafted POST requests to trigger a crash and confirms the impact using ICMP (ping) checks.
CVE-2025-7795HIGH19 Jul 2025
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RISK
open
VulnCheck XDB
infoleak
CVE-2024-20767HIGHunder attack19 Jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack18 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
Joelp03/CVE-2025-49113
CVE-2025-49113CRITICALunder attack18 Jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALunder attack18 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2021-3156HIGHunder attack18 Jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC32
POC of CVE-2025-7783
CVE-2025-7783CRITICAL18 Jul 2025
Usage of unsafe random function in form-data for choosing boundary
48RISK
open
GitHub PoC1
Zenar CMS 9.3 suffers from an ​​unrestricted file upload vulnerability​​ in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server.
CVE-2022-44136CRITICAL18 Jul 2025
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISK
open
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2025-32463CRITICALunder attack18 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-47176HIGH18 Jul 2025
Microsoft Outlook Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack18 Jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack18 Jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
simplyfurious/CVE-2025-48384-submodule_test
CVE-2025-48384HIGHunder attack17 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack17 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
admin-ping/CVE-2025-48384-RCE
CVE-2025-48384HIGHunder attack17 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC1
blindma1den/CVE-2025-47812
CVE-2025-47812CRITICALunder attack17 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
This is the exploit for the CVE-2025-32463
CVE-2025-32463CRITICALunder attack17 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack17 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
PoC of cve-2016-6210
CVE-2016-6210MEDIUM17 Jul 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISK
open
GitHub PoC
Exploit for php-cgi
CVE-2024-4577CRITICALunder attackransomware16 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
Exploit-DB
Microsoft Graphics Component Windows 11 Pro (Build 26100+) - Local Elevation of Privileges
CVE-2025-49744HIGHlocalwindows16 Jul 2025
Windows Graphics Component Elevation of Privilege Vulnerability
41RISK
open
previouspage 231 / 2,531next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.