Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
80,930 exploits
GitHub PoC
CVE-2025-47812
CVE-2025-47812CRITICALunder attack08 Sep 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC1
Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization Remote Code Execution (RCE) – CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware08 Sep 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
local
CVE-2025-21333HIGHunder attack08 Sep 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC3
PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.
CVE-2025-32433CRITICALunder attack07 Sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
local
CVE-2025-7771HIGH07 Sep 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC11
CVE-2025-7771 ThrottleStop.sys privilege escalation exploit - unrestricted IOCTL access to physical memory via MmMapIoSpace
CVE-2025-7771HIGH07 Sep 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC
Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053
CVE-2019-905307 Sep 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC2
CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains how attackers can escape container boundaries, compromise AI workloads, and how tools like Sentinel can detect and mitigate the threat
CVE-2025-23266CRITICAL07 Sep 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISK
open
GitHub PoC3
This is CVE-2025-53690 Analysis Documents.
CVE-2025-53690CRITICALunder attack07 Sep 2025
Sitecore Products ViewState Deserialization Vulnerability
90RISK
open
GitHub PoC
CTY-Research-1/CVE-2025-47812_Lab_environment
CVE-2025-47812CRITICALunder attack07 Sep 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack07 Sep 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-52970HIGH07 Sep 2025
A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.
56RISK
open
GitHub PoC
PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape
CVE-2024-28397MEDIUM06 Sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC
cve-2025-33073/cve-2025-33073
CVE-2025-33073HIGHunder attack06 Sep 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC6
exploit SQL injection ELEX WooCommerce Google Shopping
CVE-2025-10046MEDIUM06 Sep 2025
ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
33RISK
open
GitHub PoC
This repository contains a Metasploit module implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
CVE-2008-4250CRITICALunder attack06 Sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
GitHub PoC2
FOGProject Authentication bypass CVE-2025-58443 Exploit
CVE-2025-58443CRITICAL06 Sep 2025
FOG's authentication bypass leads to full SQL DB dump
68RISK
open
GitHub PoC
tranphuc2005/CVE-2023-22515
CVE-2023-22515CRITICALunder attackransomware06 Sep 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC2
PoC for CVE-2015-5736
CVE-2015-573606 Sep 2025
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RISK
open
VulnCheck XDB
initial-access
CVE-2025-58443CRITICAL06 Sep 2025
FOG's authentication bypass leads to full SQL DB dump
68RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-54309CRITICALunder attack06 Sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
GitHub PoC3
This repository contains some python scripts implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic remote code execution vulnerability affecting older Windows systems.
CVE-2008-4250CRITICALunder attack06 Sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
GitHub PoC
oukridrig772/-WinVerifyTrust-Signature-Validation-CVE-2013-3900-Mitigation
CVE-2013-3900MEDIUMunder attack06 Sep 2025
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC
whisperer1290/CVE-2025-54309__Enhanced_exploit
CVE-2025-54309CRITICALunder attack06 Sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware06 Sep 2025
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALunder attack06 Sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
GitHub PoC
PoC exploit for CVE-2024-28397 – Remote Code Execution in pyload-ng via js2py sandbox escape
CVE-2024-28397MEDIUM06 Sep 2025
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC
MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION
CVE-2017-5638CRITICALunder attackransomware06 Sep 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALunder attack06 Sep 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
GitHub PoC
shoucheng3/ff4j__ff4j_CVE-2022-44262_1_8_13_fixed
CVE-2022-44262CRITICAL06 Sep 2025
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
48RISK
open
previouspage 274 / 2,698next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.