Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
75,902 exploits
GitHub PoC
yaleman/cve-2025-24813-poc
CVE-2025-24813CRITICALunder attack03 Jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC6
Exploit for CVE-2025-6019
CVE-2025-6018HIGH03 Jul 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open
GitHub PoC1
iamgithubber/CVE-2025-6018-19-exploit
CVE-2025-6018HIGH03 Jul 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open
GitHub PoC11
This repository contains a Proof of Concept (PoC) exploit for the **CVE-2025-47175** vulnerability found in Microsoft PowerPoint. The vulnerability is a Use-After-Free (UAF) bug that allows an attacker to execute arbitrary code by tricking a user into opening a specially crafted PPTX file.
CVE-2025-47175HIGH02 Jul 2025
Microsoft PowerPoint Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
infoleak
CVE-2021-41773HIGHunder attackransomware02 Jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC3
Wing FTP Server RCE via Lua Injection
CVE-2025-47812CRITICALunder attack02 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
Exploit-DB
gogs 0.13.0 - Remote Code Execution (RCE)
CVE-2024-39930CRITICALremotemultiple02 Jul 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISK
open
GitHub PoC
robbert1978/CVE-2025-32463_POC
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
zhaduchanhzz/CVE-2025-32463_POC
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC3
Exploit for Local Privilege Escalation in Sudo via Malicious nsswitch.conf with sudo -R. (CVE-2025-32463)
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
neko205-mx/CVE-2025-32463_Exploit
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC469
Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC4
SysMancer/CVE-2025-32463
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
CVE-2025-6934 POC
CVE-2025-6934CRITICAL02 Jul 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
GitHub PoC
Python exploit for CVE-2021-41773 - Apache HTTP Server 2.4.49 Path Traversal vulnerability
CVE-2021-41773HIGHunder attackransomware02 Jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Exploit-DB
Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
CVE-2025-47812CRITICALunder attackremotemultiple02 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
B1gN0Se/Tomcat-CVE-2025-31650
CVE-2025-31650HIGH02 Jul 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISK
open
GitHub PoC1
MAVRICK-1/cve-2024-23113-test-env
CVE-2024-23113CRITICALunder attack02 Jul 2025
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
90RISK
open
Exploit-DB
Microsoft SharePoint 2019 - NTLM Authentication
CVE-2025-47166HIGHremotewindows02 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack02 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack02 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack02 Jul 2025
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Find out a modified Cacti public exploit!
CVE-2022-46169CRITICALunder attack02 Jul 2025
Unauthenticated Command Injection
100RISK
open
Exploit-DB
Moodle 4.4.0 - Authenticated Remote Code Execution
CVE-2024-43425HIGHwebappsmultiple02 Jul 2025
Moodle: remote code execution via calculated question types
78RISK
open
GitHub PoC
DirtyPipe (CVE-2022-0847) exploit written in Rust
CVE-2022-0847HIGHunder attack01 Jul 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC2
WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution
CVE-2025-49029CRITICAL01 Jul 2025
WordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
63RISK
open
previouspage 242 / 2,531next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.