Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,842cataloged exploits
37,493CVEs with public exploitation
24,695lab-tested
80,842 exploits
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL15 Oct 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH15 Oct 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC
Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)
CVE-2017-10271HIGHunder attackransomware15 Oct 2025
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC1
This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.
CVE-2021-2476215 Oct 2025
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-2476215 Oct 2025
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RISK
open
GitHub PoC11
BYOVD research performed by KOSEC. Includes vulnerable drivers and writeups (CVE-2026-0828).
CVE-2026-0828HIGH15 Oct 2025
Kernel driver vulnerability in Safetica Endpoint Client
41RISK
open
GitHub PoC
Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.
CVE-2025-29927CRITICAL15 Oct 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2017-10271HIGHunder attackransomware15 Oct 2025
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC151
Exploit for CVE-2025-11001 or CVE-2025-11002
CVE-2025-11001HIGH15 Oct 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC
CVE-2024-53677 관련 컨설턴트용 툴 개발
CVE-2024-53677CRITICAL15 Oct 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
Metasploit500
Windows Server Update Service Deserialization Remote Code Execution
CVE-2025-59287CRITICALunder attack14 Oct 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2025-4123 Grafana Open Redirect Exploit
CVE-2025-4123HIGH14 Oct 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
GitHub PoC3
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
CVE-2025-7441CRITICAL14 Oct 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-7441CRITICAL14 Oct 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
client-side
CVE-2025-6554HIGHunder attack14 Oct 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-39682CRITICAL14 Oct 2025
tls: fix handling of zero-length records on the rx_list
48RISK
open
VulnCheck XDB
client-side
CVE-2025-4123HIGH14 Oct 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
GitHub PoC
CVE-2025-24893 tool
CVE-2025-24893CRITICALunder attack14 Oct 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack14 Oct 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC4
A scanner and testter of the CVE-2025-11001 of 7-zip
CVE-2025-11001HIGH14 Oct 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC1
Poc for CVE-2024-36971
CVE-2024-36971HIGHunder attack14 Oct 2025
net: fix __dst_negative_advice() race
71RISK
open
GitHub PoC19
PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.
CVE-2025-25198HIGH14 Oct 2025
mailcow: dockerized vulnerable to password reset poisoning
41RISK
open
VulnCheck XDB
local
CVE-2025-11001HIGH14 Oct 2025
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability
46RISK
open
GitHub PoC
CVE-2024-46256 tool
CVE-2024-46256CRITICAL14 Oct 2025
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add
48RISK
open
GitHub PoC
Captures password reset tokens from Mailcow Host header injection attacks.
CVE-2025-25198HIGH14 Oct 2025
mailcow: dockerized vulnerable to password reset poisoning
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack14 Oct 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
This script checks if an HP iLO server is vulnerable and can add an admin user
CVE-2017-1254213 Oct 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
GitHub PoC
laachy/CVE-2024-39930-ptrace-detection-mitigation
CVE-2024-39930CRITICAL13 Oct 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISK
open
VulnCheck XDB
infoleak
CVE-2025-61884HIGHunder attackransomware13 Oct 2025
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions
100RISK
open
GitHub PoC
Tnot123/cve-2024-43425
CVE-2024-43425HIGH13 Oct 2025
Moodle: remote code execution via calculated question types
78RISK
open
previouspage 262 / 2,695next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.