Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,066cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
76,008 exploits
VulnCheck XDB
initial-access
CVE-2025-47539CRITICAL17 May 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RISK
open
VulnCheck XDB
local
CVE-2025-0288HIGH17 May 2025
CVE-2025-0288
41RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack16 May 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-4428HIGHunder attack16 May 2025
Remote Code Execution
100RISK
open
GitHub PoC
Software Vulnerabilities and mitigation university course, to show exploitation and remediation caused by this vulnerability
CVE-2021-4034HIGHunder attack16 May 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC2
WordPress PSW Front-end Login &amp; Registration Plugin <= 1.12 is vulnerable to Broken Authentication
CVE-2025-47646CRITICAL16 May 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISK
open
GitHub PoC
CyprianAtsyor/LetsDefend-CVE-2022-41082-Exploitation-Attempt
CVE-2022-41082HIGHunder attackransomware16 May 2025
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
GadaLuBau1337/CVE-2025-32583
CVE-2025-32583CRITICAL16 May 2025
WordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
53RISK
open
GitHub PoC4
Ivanti EPMM Pre-Auth RCE Chain
CVE-2025-4428HIGHunder attack16 May 2025
Remote Code Execution
100RISK
open
GitHub PoC
PenguinCabinet/CVE-2024-4367-hands-on
CVE-2024-4367MEDIUM16 May 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
Metasploit600
Invision Community 5.0.6 customCss RCE
CVE-2025-47916CRITICAL16 May 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The
85RISK
open
GitHub PoC11
watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428
CVE-2025-4427MEDIUMunder attack15 May 2025
Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack15 May 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack15 May 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload
CVE-2024-51793CRITICAL15 May 2025
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-4428HIGHunder attack15 May 2025
Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-4427MEDIUMunder attack15 May 2025
Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3605CRITICAL15 May 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISK
open
GitHub PoC2
演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。
CVE-2025-29927CRITICAL15 May 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment
CVE-2023-20198CRITICALunder attack15 May 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC1
CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass
CVE-2025-4094CRITICAL15 May 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RISK
open
GitHub PoC2
WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)
CVE-2025-4094CRITICAL15 May 2025
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RISK
open
GitHub PoC1
GadaLuBau1337/CVE-2025-3605
CVE-2025-3605CRITICAL15 May 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISK
open
GitHub PoC
fatkz/CVE-2020-17530
CVE-2020-17530CRITICALunder attack14 May 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
GitHub PoC
This contains single-file exploit for cve-2021-4034 which is a Polkit Local Privilege Escalation. Use it wisely!
CVE-2021-4034HIGHunder attack14 May 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
This contains single-file exploit for ProFTPd 1.3.5 mod_copy (CVE-2015-3306) vulnerability, especially for TryHackMe Kenobi Lab.
CVE-2015-330614 May 2025
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC29
encrypter15/CVE-2025-29824
CVE-2025-29824HIGHunder attackransomware14 May 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
local
CVE-2025-29824HIGHunder attackransomware14 May 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-27636MEDIUM14 May 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
55RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack14 May 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
previouspage 261 / 2,534next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.