Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,842cataloged exploits
37,493CVEs with public exploitation
24,695lab-tested
80,842 exploits
GitHub PoC
Juniper JunOS J-Web PHP external variable modification (CVE-2023-36845) exploit.
CVE-2023-36845CRITICALunder attack24 Nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
GitHub PoC
IS8123/CVE-2025-54381
CVE-2025-54381CRITICAL24 Nov 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RISK
open
VulnCheck XDB
initial-access
CVE-2023-36845CRITICALunder attack24 Nov 2025
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-845124 Nov 2025
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH24 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC1
A easy poc for CVE-2024-12084.
CVE-2024-12084CRITICAL24 Nov 2025
Rsync: heap buffer overflow in rsync due to improper checksum length handling
70RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-24054MEDIUMunder attack23 Nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC2
Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure
CVE-2025-24054MEDIUMunder attack23 Nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC
CVE-2025-11833 Checker
CVE-2025-11833CRITICAL23 Nov 2025
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-5777CRITICALunder attackransomware23 Nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC
rashedhasan090/CVE-2025-5777
CVE-2025-5777CRITICALunder attackransomware23 Nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC1
This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution, network forensics, IOC extraction, MITRE ATT&CK mapping, dropped files review, and detection rules. Evidence screenshots are included inside the evidence folder for professional documentation.
CVE-2017-0199HIGHunder attackransomware23 Nov 2025
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RISK
open
GitHub PoC1
CVE-2025-10230 PoC - Samba WINS Hook Command Injection
CVE-2025-10230CRITICAL23 Nov 2025
Samba: command injection in wins server hook script
60RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH22 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC
ranasen-rat/CVE-2025-11001
CVE-2025-11001HIGH22 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC
Custom Docker Image
CVE-2017-7494CRITICALunder attackransomware22 Nov 2025
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
GitHub PoC7
CVE-2025-11001 (CVSS 7.0) – 7-Zip < 25.00 Directory Traversal → RCE via crafted ZIP with symlink. Allows arbitrary file write when extracted as Administrator. Fixed in 7-Zip 25.00 (July 2025).
CVE-2025-11001HIGH22 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH22 Nov 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC4
CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025. Authorized testing only.
CVE-2025-26633HIGHunder attackransomware22 Nov 2025
Microsoft Management Console Security Feature Bypass Vulnerability
83RISK
open
GitHub PoC
POC
CVE-2025-5777CRITICALunder attackransomware22 Nov 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC1
Adel-kaka-dz/cve-2025-59287
CVE-2025-59287CRITICALunder attack21 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)
CVE-2025-12735CRITICAL21 Nov 2025
CVE-2025-12735
48RISK
open
GitHub PoC
Sorumluluk Reddi Kendi sorumluluğunuzda kullanın, size ait olmayan veya tarama izninizin olmadığı altyapılarda gerçekleştireceğiniz yasa dışı faaliyetlerden sorumlu olmayacağım.
CVE-2025-61882CRITICALunder attackransomware21 Nov 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
GitHub PoC1
SAP RCE auto-chain (CVE-2024-22127 + DIAG)
CVE-2024-22127CRITICAL21 Nov 2025
Code Injection vulnerability in SAP NetWeaver AS Java (Administrator Log Viewer plug-in)
48RISK
open
GitHub PoC1
Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table, three hunts (KQL/SPL/Sigma), first-4-hours comms, sample data, and figures. Built for fast triage; no org data; SharePoint Online out of scope.
CVE-2025-53770CRITICALunder attackransomware21 Nov 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Proof‑of‑concept description for CVE‑2025‑47916, a Remote Code Execution vulnerability affecting Invision Community 5.0.0–5.0.6 via unsafe template processing in the "customCss()" method.
CVE-2025-47916CRITICAL21 Nov 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack21 Nov 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47916CRITICAL21 Nov 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISK
open
GitHub PoC4
Oracle Identity Manager 远程代码执行漏洞CVE-2025-61757
CVE-2025-61757CRITICALunder attack21 Nov 2025
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack21 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
previouspage 250 / 2,695next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.