Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
80,930 exploits
VulnCheck XDB
infoleak
CVE-2024-48307CRITICAL31 Aug 2025
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD
75RISK
open
GitHub PoC18
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
CVE-2025-7771HIGH31 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC
CTF_WRITEUPS/TryHackMe /CVE-2021-41773/
CVE-2021-41773HIGHunder attackransomware31 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Detection for CVE-2025-4427 and CVE-2025-4428
CVE-2025-4427MEDIUMunder attack31 Aug 2025
Authentication Bypass
100RISK
open
GitHub PoC2
Detection for CVE-2025-7775
CVE-2025-7775CRITICALunder attack31 Aug 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISK
open
VulnCheck XDB
local
CVE-2025-7771HIGH31 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC19
Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast
CVE-2025-24813CRITICALunder attack31 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack31 Aug 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
client-side
CVE-2015-925131 Aug 2025
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware31 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have tweaked the chain from a simple DLL to a full reverse‑shell stack, and what that means for the defenders.
CVE-2025-2776CRITICALunder attack31 Aug 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RISK
open
GitHub PoC18
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
CVE-2025-7771HIGH31 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC5
Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction.
CVE-2025-24201CRITICALunder attack30 Aug 2025
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in
78RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack30 Aug 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC
Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization
CVE-2025-49113CRITICALunder attack30 Aug 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC4
PHPUnit CVE-2017-9841 Scanner in Go clean and fire.
CVE-2017-9841CRITICALunder attack30 Aug 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC
tranphuc2005/CVE-2019-3396
CVE-2019-3396CRITICALunder attackransomware30 Aug 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC6
Detects vulnerable FreePBX versions affected by CVE-2025-57819.
CVE-2025-57819CRITICALunder attack30 Aug 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC
Aaqilyousuf/CVE-2025-7775-vulnerable-lab
CVE-2025-7775CRITICALunder attack30 Aug 2025
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
83RISK
open
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALunder attackransomware30 Aug 2025
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack29 Aug 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack29 Aug 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-34040CRITICAL29 Aug 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISK
open
GitHub PoC
Python Script for CVE-2025-49113. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
CVE-2025-49113CRITICALunder attack29 Aug 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
arun1033/CVE-2025-48384
CVE-2025-48384HIGHunder attack29 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819
CVE-2025-57819CRITICALunder attack29 Aug 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC
CrushFTP AS2 Authentication Bypass
CVE-2025-54309CRITICALunder attack29 Aug 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
GitHub PoC2
致远OA存在文件上传导致RCE(CVE-2025-34040)
CVE-2025-34040CRITICAL29 Aug 2025
Seeyon Zhiyuan OA System Path Traversal File Upload
68RISK
open
GitHub PoC1
Detection for CVE-2025-57819
CVE-2025-57819CRITICALunder attack28 Aug 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-12877CRITICAL28 Aug 2025
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection
48RISK
open
previouspage 277 / 2,698next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.