Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
75,902 exploits
GitHub PoC
hdgokani/CVE-2018-1273
CVE-2018-1273CRITICALunder attackransomware25 Jun 2025
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
GitHub PoC3
ademto/wordpress-cve-2024-10924-pentest
CVE-2024-10924CRITICAL25 Jun 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.9.2 CVE-2025-47577 PoC
CVE-2025-47577CRITICAL25 Jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RISK
open
GitHub PoC
Rust Macros No Recoil Guide 🚀 Boost Aim Like a Pro in C and Python
CVE-2025-0411HIGHunder attack24 Jun 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open
GitHub PoC
A script is a PoC for CVE-2022-1257, a vulnerability in the McAfee Agent (Trellix Agent) when working with it's database. The vulnerability allows attackers to retrieve and decrypt credentials from the McAfee Agent database file (`ma.db`) due to improper encryption key handling.
CVE-2022-1257MEDIUM24 Jun 2025
Improper Verification of Cryptographic Signature by McAfee Agent
33RISK
open
GitHub PoC
CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥
CVE-2025-4322CRITICAL24 Jun 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISK
open
GitHub PoC5
PoCs for CVE-2025-49132
CVE-2025-49132CRITICAL24 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL24 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-49132CRITICAL23 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL23 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-33538HIGHunder attack23 Jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open
VulnCheck XDB
local
CVE-2020-104823 Jun 2025
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
43RISK
open
VulnCheck XDB
initial-access
CVE-2025-1094HIGH23 Jun 2025
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware23 Jun 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC4
Pterodactyl翼龙面板CVE-2025-49132批量检测☝️🤓
CVE-2025-49132CRITICAL23 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
cuerv0x/CVE-2015-6967
CVE-2015-696723 Jun 2025
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open
GitHub PoC1
CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework
CVE-2023-33538HIGHunder attack23 Jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open
GitHub PoC2
Exploit (C) CVE-2024-4577 on PHP CGI
CVE-2024-4577CRITICALunder attackransomware23 Jun 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC2
Check a list of Pterodactyl panels for vulnerabilities from a file.
CVE-2025-49132CRITICAL23 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC3
Mass-CVE-2025-3248
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
CVE-2025-3248
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC7
Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC17
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
CVE-2025-49132CRITICAL22 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC1
Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability
CVE-2023-33538HIGHunder attack22 Jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open
GitHub PoC1
sendINUX/CVE-2021-22600__DirtyPagetable
CVE-2021-22600MEDIUMunder attack22 Jun 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISK
open
GitHub PoC
gmh5225/CVE-2025-1562
CVE-2025-1562CRITICAL22 Jun 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISK
open
GitHub PoC
CVE 2018-9035: CSV Injection in Wordpress with plugin Contact Form 7 to Database Extension 2.10.3
CVE-2018-903522 Jun 2025
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware22 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
previouspage 246 / 2,531next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.