Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
80,930 exploits
GitHub PoC1
CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1
CVE-2016-15042CRITICAL03 Sep 2025
Frontend File Manager < 4.0 & N-Media Post Front-end Form < 1.1 & - Arbitrary File Upload
63RISK
open
VulnCheck XDB
local
CVE-2015-132803 Sep 2025
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack03 Sep 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
GitHub PoC8
New vulnerability found in Docker. Credit for finding the vulnerability goes to Felix Boulet
CVE-2025-9074CRITICAL03 Sep 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH03 Sep 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
GitHub PoC11
b0ySie7e/CVE-2025-24893
CVE-2025-24893CRITICALunder attack03 Sep 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware03 Sep 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
This repository provides a modified version of the original CVE-2017-6074 exploit (use-after-free in the Linux kernel DCCP subsystem), designed only to demonstrate Denial of Service (DoS) impact. An authenticated local user can trigger a kernel panic, causing a total loss of system availability.
CVE-2017-607403 Sep 2025
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RISK
open
GitHub PoC
This is a PoC for the CVE-2025-24813 and tested in different environments.
CVE-2025-24813CRITICALunder attack03 Sep 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC1
This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln
CVE-2024-47875CRITICAL02 Sep 2025
DOMPurify nesting-based mXSS
48RISK
open
GitHub PoC1
CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit
CVE-2025-23266CRITICAL02 Sep 2025
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, wher
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-51568CRITICAL02 Sep 2025
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISK
open
GitHub PoC2
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL02 Sep 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
GitHub PoC
Python3 port of the original Joomla Core (1.5.0 through 3.9.4) - Directory Traversal && Authenticated Arbitrary File Deletion
CVE-2019-1094502 Sep 2025
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RISK
open
GitHub PoC1
jsnv-dev/CVE-2024-51568---CyberPanel-Command-Injection-Nuclei-Template
CVE-2024-51568CRITICAL02 Sep 2025
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut
75RISK
open
GitHub PoC1
Version detection PowerShell
CVE-2025-7775CRITICALunder attack02 Sep 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISK
open
VulnCheck XDB
infoleak
CVE-2025-57819CRITICALunder attack01 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-34300CRITICAL01 Sep 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
85RISK
open
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware01 Sep 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALunder attack01 Sep 2025
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-11357CRITICALunder attackransomware01 Sep 2025
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack01 Sep 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3515HIGH01 Sep 2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RISK
open
GitHub PoC1
a proof of concept of CVE-2024-53677
CVE-2024-53677CRITICAL01 Sep 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
initial-access
CVE-2018-1920701 Sep 2025
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL01 Sep 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC1
Sawtooth Lighthouse Studio存在模板注入漏洞CVE-2025-34300
CVE-2025-34300CRITICAL01 Sep 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
85RISK
open
GitHub PoC1
HTML cache poisoning through unsafe reflections
CVE-2025-53693CRITICAL01 Sep 2025
HTML Cache Poisoning through Unsafe Reflections
53RISK
open
GitHub PoC7
FreePBX SQL Injection Exploit
CVE-2025-57819CRITICALunder attack01 Sep 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
local
CVE-2025-7771HIGH31 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
previouspage 276 / 2,698next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.