Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,008cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
76,008 exploits
GitHub PoC
CyberBibs/Event-ID-263-Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-
CVE-2024-24919HIGHunder attackransomware08 Jun 2025
Information disclosure
100RISK
open
GitHub PoC
CVE-2024-51482 ZoneMinder v1.37.* <= 1.37.64 poc
CVE-2024-51482CRITICAL07 Jun 2025
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC1
CVE-2017-5638 Exploit Rewritten In Python By haxerr9
CVE-2017-5638CRITICALunder attackransomware07 Jun 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
CVE-2025-31161
CVE-2025-31161CRITICALunder attackransomware07 Jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL07 Jun 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware07 Jun 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-0282CRITICALunder attackransomware07 Jun 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
GitHub PoC
CVE-2025-31131
CVE-2025-31131HIGH07 Jun 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RISK
open
Metasploit600
Skyvern SSTI Remote Code Execution
CVE-2025-49619HIGH07 Jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack06 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware06 Jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH06 Jun 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM06 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-14871CRITICALunder attack06 Jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
VulnCheck XDB
client-side
CVE-2025-4123HIGH06 Jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware06 Jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack06 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
🚨 Exploit CVE-2025-55182 to demonstrate RCE in React Server Functions, highlighting risks from insecure prototype references in Next.js applications.
CVE-2025-55182CRITICALunder attackransomware06 Jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
This is a little Python script to detect the "EvilSun" vulnerability (CVE-2020-14871) on Solaris systems. The vulnerability is a buffer overflow in the Pluggable Authentication Module (PAM) `pam_unix_auth` when handling keyboard-interactive authentication in SSH.
CVE-2020-14871CRITICALunder attack06 Jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
GitHub PoC18
mbanyamer/CVE-2025-24076
CVE-2025-24076HIGH06 Jun 2025
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC2
CVE-2025-49113 exploit
CVE-2025-49113CRITICALunder attack06 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC92
Proof of Concept demonstrating Remote Code Execution through insecure deserialization in Roundcube (CVE-2025-49113).
CVE-2025-49113CRITICALunder attack06 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
POC
CVE-2025-30208MEDIUM06 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
Exploit-DB
CloudClassroom PHP Project 1.0 - SQL Injection
CVE-2025-45542HIGHwebappsphp05 Jun 2025
SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v
41RISK
open
GitHub PoC3
rasool13x/exploit-CVE-2025-49113
CVE-2025-49113CRITICALunder attack05 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
Exploit-DB
Microsoft Windows Server 2025 JScript Engine - Remote Code Execution (RCE)
CVE-2025-30397HIGHunder attackremotewindows05 Jun 2025
Scripting Engine Memory Corruption Vulnerability
76RISK
open
Exploit-DB
Apache Tomcat 10.1.39 - Denial of Service (DoS)
CVE-2025-31650HIGHremotemultiple05 Jun 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
53RISK
open
GitHub PoC
PoC for CVE-2024-42049
CVE-2024-42049CRITICAL05 Jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-32756CRITICALunder attack05 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack05 Jun 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
previouspage 254 / 2,534next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.