Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,902cataloged exploits
34,597CVEs with public exploitation
24,695lab-tested
75,902 exploits
GitHub PoC
Rust PoC for CVE-2025-32463 (sudo chroot "chwoot" Local PrivEsc)
CVE-2025-32463CRITICALunder attack11 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers
CVE-2024-4577CRITICALunder attackransomware11 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
r0otk3r/CVE-2024-10915
CVE-2024-10915CRITICAL11 Jul 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
GitHub PoC
p1026/CVE-2025-48384
CVE-2025-48384HIGHunder attack11 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC6
CVE-2025-24201 WebKit Vulnerability Detector (PoC)
CVE-2025-24201CRITICALunder attack11 Jul 2025
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in
78RISK
open
GitHub PoC
Critical Sudo Vulnerabilities Let Local Users Gain Root Access on Linux, Impacting Major Distros
CVE-2025-32462LOW11 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC1
PoC dockerfile image for CVE-2025-48384
CVE-2025-48384HIGHunder attack11 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
Documentation for CVE-2025-6514. MCP-Remote RCE.
CVE-2025-6514CRITICAL11 Jul 2025
OS command injection in mcp-remote when connecting to untrusted MCP servers
70RISK
open
GitHub PoC
Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE
CVE-2022-36934CRITICAL11 Jul 2025
An integer overflow in WhatsApp could result in remote code execution in an established video call.
48RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack11 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
cuijiung/log4j-CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware11 Jul 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack11 Jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-25257CRITICALunder attack11 Jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
VulnCheck XDB
client-side
CVE-2025-24201CRITICALunder attack11 Jul 2025
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALunder attack11 Jul 2025
Apache OFBiz: Path traversal leading to RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack11 Jul 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC
This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.
CVE-2014-6287CRITICALunder attack11 Jul 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC
just remeber how small mistake in santisize username could give yoy root access to the full machine
CVE-2007-244711 Jul 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware11 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware10 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack10 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
client-side
CVE-2025-6218HIGHunder attack10 Jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware10 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
漏洞测试
CVE-2025-48384HIGHunder attack10 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
CVE-2025-6554 PoC
CVE-2025-6554HIGHunder attack10 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
71RISK
open
GitHub PoC18
CVE-2025-6218 is a directory traversal vulnerability in WinRAR that allows an attacker to place files outside the intended extraction directory when a user extracts a specially crafted
CVE-2025-6218HIGHunder attack10 Jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
GitHub PoC100
watchtowrlabs/watchTowr-vs-FortiWeb-CVE-2025-25257
CVE-2025-25257CRITICALunder attack10 Jul 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
previouspage 235 / 2,531next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.