Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
80,930 exploits
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALunder attack18 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC
There are Exploit for Magnus Billing v7 system get root privilages
CVE-2023-30258CRITICAL18 Sep 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack18 Sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC2
This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract credentials using sqlmap (poc_auto_get_username_pass.py). For educational and authorized use only.
CVE-2025-57819CRITICALunder attack18 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC1
test
CVE-2025-32433CRITICALunder attack18 Sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions
CVE-2010-124017 Sep 2025
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
GitHub PoC1
Proof-Of-Concept to check privileges of af_packet.c for validating the privileges acquired by any hacker upon successful exploitation of CVE-2021-22600
CVE-2021-22600MEDIUMunder attack17 Sep 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISK
open
VulnCheck XDB
client-side
CVE-2010-124017 Sep 2025
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
GitHub PoC
PoC for achieving RCE in Langflow versions <1.3.0
CVE-2025-3248CRITICALunder attackransomware17 Sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware17 Sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
This repository contains a Proof of Concept (PoC) for CVE-2024-28397, a vulnerability in the js2py library allowing a sandbox escape to achieve remote code execution.
CVE-2024-28397MEDIUM17 Sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC
CVE-2024-28397 - Remote Code Execution From Vulnerable JS2PY
CVE-2024-28397MEDIUM17 Sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC1
Shinkirou789/Cve-2025-8088-WinRar-vulnerability
CVE-2025-8088HIGHunder attackransomware17 Sep 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
do not use. vulnerable
CVE-2025-29927CRITICAL17 Sep 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL17 Sep 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
local
CVE-2021-22600MEDIUMunder attack17 Sep 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISK
open
Exploit-DB
HTTP/2 2.0 - Denial Of Service (DOS)
CVE-2023-44487HIGHunder attackremotemultiple16 Sep 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
Exploit-DB
ClipBucket 5.5.0 - Arbitrary File Upload
CVE-2025-55912HIGHremotemultiple16 Sep 2025
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in
41RISK
open
GitHub PoC
A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.
CVE-2014-6287CRITICALunder attack16 Sep 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALunder attackransomware16 Sep 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
Exploit-DB
Mbed TLS 3.6.4 - Use-After-Free
CVE-2025-47917HIGHlocalmultiple16 Sep 2025
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack16 Sep 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-1709CRITICALunder attackransomware16 Sep 2025
Authentication bypass using an alternate path or channel
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-1708HIGHunder attackransomware16 Sep 2025
Improper limitation of a pathname to a restricted directory (“path traversal”)
100RISK
open
GitHub PoC2
RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。
CVE-2018-20062CRITICALunder attack16 Sep 2025
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RISK
open
Exploit-DB
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
CVE-2025-24893CRITICALunder attackwebappsmultiple16 Sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
2 web apps vulnerable to CVE-2025-27210
CVE-2025-27210HIGH16 Sep 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
46RISK
open
VulnCheck XDB
infoleak
CVE-2025-24799HIGH16 Sep 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISK
open
Exploit-DB
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
CVE-2023-34927webappsmultiple16 Sep 2025
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RISK
open
Exploit-DB
Tourism Management System 2.0 - Arbitrary Shell Upload
CVE-2025-57642HIGHwebappsmultiple16 Sep 2025
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she
41RISK
open
previouspage 270 / 2,698next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.