Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
80,930 exploits
VulnCheck XDB
initial-access
CVE-2025-9242CRITICALunder attack01 Oct 2025
WatchGuard Firebox iked Out of Bounds Write Vulnerability
100RISK
open
GitHub PoC
CS50 Cybersecurity final project — Palo Alto OAuth token breach (CVE-2024-3400)
CVE-2024-3400CRITICALunder attackransomware01 Oct 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC13
watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242
CVE-2025-9242CRITICALunder attack01 Oct 2025
WatchGuard Firebox iked Out of Bounds Write Vulnerability
100RISK
open
GitHub PoC2
Kiraly07/Demo_CVE-2025-3248
CVE-2025-3248CRITICALunder attackransomware01 Oct 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
client-side
CVE-2025-43300CRITICALunder attack30 Sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
GitHub PoC1
Detection for CVE-2025-41244
CVE-2025-41244HIGHunder attack30 Sep 2025
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RISK
open
VulnCheck XDB
client-side
CVE-2025-43300CRITICALunder attack30 Sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
VulnCheck XDB
initial-access
CVE-2017-9822HIGHunder attackransomware30 Sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack30 Sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-41646CRITICAL30 Sep 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RISK
open
GitHub PoC1
A Rust implementation of the POC for CVE-2017-7269, targeting the WebDAV service in Microsoft Internet Information Services (IIS) 6.0.
CVE-2017-7269CRITICALunder attack30 Sep 2025
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALunder attack30 Sep 2025
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RISK
open
GitHub PoC1
This is POC for IOS 0click CVE-2025-43300
CVE-2025-43300CRITICALunder attack30 Sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
GitHub PoC3
ticofookfook/CVE-2025-43300
CVE-2025-43300CRITICALunder attack30 Sep 2025
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1
83RISK
open
GitHub PoC
tno01/cve-2019-3396
CVE-2019-3396CRITICALunder attackransomware30 Sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
A Python exploit for CVE-2025-32463, a critical local privilege escalation vulnerability in the Sudo binary on Linux systems. This flaw allows local users to obtain root access by exploiting the --chroot option, which incorrectly uses /etc/nsswitch.conf from a user-controlled directory.
CVE-2025-32463CRITICALunder attack30 Sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-1974CRITICAL30 Sep 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC
Tnot123/cve-2017-9822
CVE-2017-9822HIGHunder attackransomware30 Sep 2025
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RISK
open
GitHub PoC
Log4Shell (CVE-2021-44228) PoC
CVE-2021-44228CRITICALunder attackransomware29 Sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
CVE-2024-47051
CVE-2024-47051CRITICAL29 Sep 2025
Remote Code Execution & File Deletion in Asset Uploads
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-36604HIGH29 Sep 2025
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('
68RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware29 Sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware29 Sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
victormbogu1/LetsDefend-SOC342-CVE-2025-53770-SharePoint-ToolShell-Auth-Bypass-andRCE-EventID-320
CVE-2025-53770CRITICALunder attackransomware29 Sep 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-36537HIGHunder attackransomware28 Sep 2025
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISK
open
GitHub PoC
ethan-repo-lab4b6/CVE-2022-36537
CVE-2022-36537HIGHunder attackransomware28 Sep 2025
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte
100RISK
open
GitHub PoC
kuyrathdaro/cve-2025-29927
CVE-2025-29927CRITICAL28 Sep 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.
CVE-2021-44228CRITICALunder attackransomware27 Sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware27 Sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
initial-access
CVE-2009-226527 Sep 2025
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
previouspage 266 / 2,698next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.