Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
80,930 exploits
VulnCheck XDB
local
CVE-2019-6693MEDIUMunder attackransomware26 Aug 2025
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
Exploit-DB
GeoVision ASManager Windows Application 6.1.2.0 - Remote Code Execution (RCE)
CVE-2025-26264HIGHremotewindows26 Aug 2025
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RISK
open
Exploit-DB
Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
CVE-2025-6082MEDIUMwebappsmultiple26 Aug 2025
Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure
33RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attackransomware26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
initial-access
CVE-2025-34030CRITICAL26 Aug 2025
sar2html OS Command Injection
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC1
DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC
CVE-2025-8088HIGHunder attackransomware26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC1
POWERSHEL script to check if your device is affected or no
CVE-2025-8088HIGHunder attackransomware26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC12
An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist.
CVE-2025-8088HIGHunder attackransomware26 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC1
Real4XoR/CVE-2019-6693
CVE-2019-6693MEDIUMunder attackransomware26 Aug 2025
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke
63RISK
open
Exploit-DB
StoryChief Wordpress Plugin 1.0.42 - Arbitrary File Upload
CVE-2025-7441CRITICALwebappsmultiple26 Aug 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC2
Unauth RCE PoC for XWiki SolrSearch (CVE-2025-24893). Command exec + reverse shell.
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
Exploit-DB
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
CVE-2025-4427MEDIUMunder attackremotemultiple26 Aug 2025
Authentication Bypass
100RISK
open
Exploit-DB
GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
CVE-2025-26263MEDIUMlocalwindows26 Aug 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISK
open
GitHub PoC
a1ex-var1amov/ctf-cve-2019-11043
CVE-2019-11043HIGHunder attackransomware26 Aug 2025
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC
PoC for CVE-2025-34030 sar2html 'plot' parameter RCE
CVE-2025-34030CRITICAL26 Aug 2025
sar2html OS Command Injection
75RISK
open
GitHub PoC
A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
CVE-2025-24893CRITICALunder attack26 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC10
zenzue/CVE-2025-9074
CVE-2025-9074CRITICAL25 Aug 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
GitHub PoC2
Odoo ≤17 is vulnerable to CVE-2024-4367, allowing arbitrary JavaScript execution via PDF.js.
CVE-2024-4367MEDIUM25 Aug 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
PoC
CVE-2025-48384HIGHunder attack25 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC3
Apache Struts2 CVE-2017-5638 (Safe Educational Demo)
CVE-2017-5638CRITICALunder attackransomware25 Aug 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
GitHub PoC
TamatahYT/CVE-2017-8481
CVE-2017-848125 Aug 2025
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RISK
open
GitHub PoC
A research regarding the exisiting CVE exploit : CVE-2021-3156(Sudo BufferOverflow)
CVE-2021-3156HIGHunder attack25 Aug 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
his project demonstrates the exploitation of the vsFTPd 2.3.4 backdoor vulnerability (CVE-2011-2523) using Metasploitable 2 and Kali Linux with Metasploit. It includes reconnaissance, exploitation, and defensive measures, with a detailed report and lab setup for learning ethical hacking and security best practices.
CVE-2011-252325 Aug 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
a1ex-var1amov/ctf-cve-2024-4577
CVE-2024-4577CRITICALunder attackransomware25 Aug 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALunder attackransomware25 Aug 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
client-side
CVE-2025-5419HIGHunder attack25 Aug 2025
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack25 Aug 2025
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack25 Aug 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
previouspage 279 / 2,698next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.