Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,842cataloged exploits
37,493CVEs with public exploitation
24,695lab-tested
80,842 exploits
GitHub PoC
CVE-2025-21042
CVE-2025-21042HIGHunder attack11 Nov 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
83RISK
open
GitHub PoC1
Comprehensive Proof of Concept collection for CVE-2025-11953, CVE-2025-59287, CVE-2025-8941 with exploitation frameworks in Python, C, Bash, PowerShell
CVE-2025-11953CRITICALunder attack11 Nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
100RISK
open
GitHub PoC2
CVE-2025-41244 is a critical local privilege escalation vulnerability in VMware Aria Operations and VMware Tools
CVE-2025-41244HIGHunder attack11 Nov 2025
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RISK
open
GitHub PoC
Exploit cyberpanel version 2.3.6 - 2.3.7
CVE-2024-51378CRITICALunder attackransomware11 Nov 2025
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
100RISK
open
GitHub PoC
Vulnerability for Xwiki
CVE-2024-31982CRITICAL11 Nov 2025
XWiki Platform: Remote code execution as guest via DatabaseSearch
75RISK
open
GitHub PoC5
Wh04m1001/CVE-2025-60710
CVE-2025-60710HIGHunder attackransomware11 Nov 2025
Host Process for Windows Tasks Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC10
CVE-2025-55315 PoC Exploit
CVE-2025-55315CRITICAL11 Nov 2025
ASP.NET Security Feature Bypass Vulnerability
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-48703CRITICALunder attack11 Nov 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
GitHub PoC
CVE-2025-25257 PoC for educational use and/or authorised pentesting.
CVE-2025-25257CRITICALunder attack11 Nov 2025
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-3581311 Nov 2025
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experi
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-1974CRITICAL10 Nov 2025
ingress-nginx admission controller RCE escalation
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-34299CRITICAL10 Nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
GitHub PoC1
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
CVE-2025-6440CRITICAL10 Nov 2025
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
Ghstxz/CVE-2025-32463
CVE-2025-32463CRITICALunder attack10 Nov 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-11953CRITICALunder attack10 Nov 2025
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
100RISK
open
GitHub PoC
Exploit and test stand for CVE-2025-2945
CVE-2025-2945CRITICAL10 Nov 2025
pgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
75RISK
open
GitHub PoC1
check if vulnerable python-django version to CVE-2025-64459 bug
CVE-2025-64459CRITICAL10 Nov 2025
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open
GitHub PoC
A proof of concept for CVE-2025-24054/CVE-2025-24071
CVE-2025-24054MEDIUMunder attack09 Nov 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC12
CVE-2025-6554
CVE-2025-6554HIGHunder attack09 Nov 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RISK
open
GitHub PoC
n0m-d/CVE-2021-40438-POC
CVE-2021-40438CRITICALunder attackransomware09 Nov 2025
mod_proxy SSRF
100RISK
open
VulnCheck XDB
infoleak
CVE-2021-40438CRITICALunder attackransomware09 Nov 2025
mod_proxy SSRF
100RISK
open
GitHub PoC
letsr00t/-CVE-2019-18634-sudo-pwfeedback
CVE-2019-1863408 Nov 2025
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RISK
open
GitHub PoC
l1nuxkid/CVE-2025-32433-exploit
CVE-2025-32433CRITICALunder attack08 Nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
Metasploit600
FreePBX filestore authenticated command injection
CVE-2025-64328HIGHunder attack08 Nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RISK
open
GitHub PoC9
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
CVE-2025-11749CRITICAL08 Nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISK
open
VulnCheck XDB
client-side
CVE-2025-21042HIGHunder attack08 Nov 2025
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
83RISK
open
VulnCheck XDB
infoleak
CVE-2025-11749CRITICAL08 Nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack08 Nov 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack08 Nov 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-5902CRITICALunder attackransomware07 Nov 2025
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISK
open
previouspage 255 / 2,695next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.