Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
80,930 exploits
GitHub PoC
A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.
CVE-2009-226527 Sep 2025
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISK
open
GitHub PoC
CVE-2025-10035_GoAnywhere Get RCE
CVE-2025-10035CRITICALunder attackransomware27 Sep 2025
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
100RISK
open
GitHub PoC
This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.
CVE-2021-44228CRITICALunder attackransomware27 Sep 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
0xDTC/CrushFTP-auth-bypass-CVE-2025-31161
CVE-2025-31161CRITICALunder attackransomware27 Sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC
Scans target to see if its vulnerable to CVE-2025-31161
CVE-2025-31161CRITICALunder attackransomware26 Sep 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC
Analyzing CVE-2023-36802 (mskssrv.sys) - object type confusion bug
CVE-2023-36802HIGHunder attack26 Sep 2025
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC2
CVE-2024-6387 and more Checker and Exploiter - Reverse/Bind-Shell Support. education only
CVE-2024-6387HIGH26 Sep 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
VulnCheck XDB
local
CVE-2023-36802HIGHunder attack26 Sep 2025
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attackransomware26 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
local
CVE-2024-0582HIGH26 Sep 2025
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open
GitHub PoC
Microsoft HEIF Extension (msheif_store.dll) OOB-read
CVE-2025-62821CRITICAL25 Sep 2025
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc
48RISK
open
VulnCheck XDB
infoleak
CVE-2025-51591LOW25 Sep 2025
A Server-Side Request Forgery (SSRF) in JGM Pandoc v3.6.4 allows attackers to gain access to and compromise the whole in
28RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL25 Sep 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC8
CVE-2025-8088 exploit C++ impl
CVE-2025-8088HIGHunder attackransomware25 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
CVE-2017-5638- PoC
CVE-2017-5638CRITICALunder attackransomware25 Sep 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
Example script demonstrating a weak PRNG, CVE-2008-0166
CVE-2008-016625 Sep 2025
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISK
open
GitHub PoC
CVE-2025-49132
CVE-2025-49132CRITICAL25 Sep 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC1
JS Archive List <= 6.1.5 - Unauthenticated SQL Injection
CVE-2025-54726CRITICAL25 Sep 2025
WordPress JS Archive List Plugin < 6.1.6 - SQL Injection Vulnerability
63RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attackransomware25 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
infoleak
CVE-2025-54726CRITICAL25 Sep 2025
WordPress JS Archive List Plugin < 6.1.6 - SQL Injection Vulnerability
63RISK
open
GitHub PoC6
CVE-2025-20352 SNMP Exposure Check (onesixtyone + parser)
CVE-2025-20352HIGHunder attack25 Sep 2025
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa
83RISK
open
GitHub PoC
iteride/CVE-2025-2294
CVE-2025-2294CRITICAL24 Sep 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC
CVE-2025-34100 test
CVE-2025-34100CRITICAL24 Sep 2025
BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
63RISK
open
GitHub PoC2
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
CVE-2025-56819CRITICAL24 Sep 2025
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
63RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack24 Sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
CVE-2025-57174 Unauthenticated Remote Command Execution
CVE-2025-57174CRITICAL24 Sep 2025
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and p
48RISK
open
GitHub PoC
RCE project
CVE-2017-1261124 Sep 2025
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RISK
open
GitHub PoC
This repository contains a Proof of Concept (PoC) for CVE-2025-32463, a vulnerability in sudo allowing a chroot escape to achieve local privilege escalation.
CVE-2025-32463CRITICALunder attack24 Sep 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
CVE-2025-57176 - Siklu EtherHaul Series - Unauthenticated Arbitrary File Upload
CVE-2025-57176MEDIUM24 Sep 2025
On Ceragon Networks / Siklu Communication EtherHaul and MultiHaul Series microwave antennas before 2026-03-10, the rfpip
33RISK
open
GitHub PoC
Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)
CVE-2018-7600CRITICALunder attackransomware24 Sep 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
previouspage 267 / 2,698next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.