Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,842cataloged exploits
37,493CVEs with public exploitation
24,695lab-tested
80,842 exploits
VulnCheck XDB
initial-access
CVE-2017-1254213 Oct 2025
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RISK
open
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 Oct 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
VulnCheck XDB
local
CVE-2023-29360HIGHunder attack12 Oct 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
Scottman625/CVE-2023-29360
CVE-2023-29360HIGHunder attack12 Oct 2025
Microsoft Streaming Service Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC1
PoC of "DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste"
CVE-2024-27304CRITICAL12 Oct 2025
pgx SQL Injection via Protocol Message Size Overflow
48RISK
open
GitHub PoC1
Reverse shell for CVE-2024-28397.
CVE-2024-28397MEDIUM12 Oct 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC7
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
CVE-2025-32463CRITICALunder attack12 Oct 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941
CVE-2017-594112 Oct 2025
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RISK
open
VulnCheck XDB
initial-access
CVE-2021-4328711 Oct 2025
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default,
43RISK
open
VulnCheck XDB
initial-access
CVE-2025-11371HIGHunder attack11 Oct 2025
Gladinet CentreStack and TrioFox Local File Inclusion Flaw
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-46982HIGH11 Oct 2025
Cache Poisoning in next.js
53RISK
open
VulnCheck XDB
initial-access
CVE-2025-61882CRITICALunder attackransomware10 Oct 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
GitHub PoC3
CVE-2024-38856: Apache OFBiz remote code execution Scanner & Exploit
CVE-2024-38856HIGHunder attack10 Oct 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-2539HIGH10 Oct 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISK
open
VulnCheck XDB
initial-access
CVE-2025-5947CRITICAL10 Oct 2025
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-38856HIGHunder attack10 Oct 2025
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
100RISK
open
GitHub PoC
CVE-2024-32113-Apache-OFBiz<18.12.13-Exploit
CVE-2024-32113CRITICALunder attack09 Oct 2025
Apache OFBiz: Path traversal leading to RCE
100RISK
open
GitHub PoC
- Vulnerable: sudo 1.9.14, 1.9.15, 1.9.16, 1.9.17 - Patched in: sudo 1.9.17p1 and later - Legacy versions older than 1.9.14 are not affected, as they don't support the --chroot option.
CVE-2025-32463CRITICALunder attack09 Oct 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Enviroment and Nuclei template to test CVE-2025-32463
CVE-2025-32463CRITICALunder attack09 Oct 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-49844CRITICAL09 Oct 2025
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware09 Oct 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC
syorik/CVE-2023-42793
CVE-2023-42793CRITICALunder attackransomware09 Oct 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
GitHub PoC2
CVE-2023-21554 PoC
CVE-2023-21554CRITICAL09 Oct 2025
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
85RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attackransomware09 Oct 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
initial-access
CVE-2024-32113CRITICALunder attack09 Oct 2025
Apache OFBiz: Path traversal leading to RCE
100RISK
open
GitHub PoC
foregenix/CVE-2023-39143
CVE-2023-39143CRITICAL09 Oct 2025
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
85RISK
open
Metasploit600
SmarterTools SmarterMail GUID File Upload Vulnerability
CVE-2025-52691CRITICALunder attackransomware09 Oct 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC
sudo --chroot exploit
CVE-2025-32463CRITICALunder attack08 Oct 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
Reproduction and fix of the CVE-2025-29927 vulnerability.
CVE-2025-29927CRITICAL08 Oct 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-10353CRITICAL08 Oct 2025
Missing Authorization vulnerability in Melis Platform
63RISK
open
previouspage 263 / 2,695next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.