Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,930cataloged exploits
37,572CVEs with public exploitation
24,695lab-tested
80,930 exploits
GitHub PoC
shoucheng3/jmrozanec__cron-utils_CVE-2021-41269_9-1-5
CVE-2021-41269CRITICAL20 Aug 2025
Unauthenticated remote code injection in cron-utils
48RISK
open
GitHub PoC
harshitvarma05/CVE-2025-31324-Exploits
CVE-2025-31324CRITICALunder attackransomware20 Aug 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
GitHub PoC
shoucheng3/apache__flink_CVE-2020-17519_1-11-2
CVE-2020-17519CRITICALunder attack20 Aug 2025
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
VulnCheck XDB
client-side
CVE-2025-8088HIGHunder attackransomware19 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC8
Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution
CVE-2025-8723CRITICAL19 Aug 2025
Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook
53RISK
open
GitHub PoC
shoucheng3/apache__dolphinscheduler_CVE-2023-49109_3-2-0
CVE-2023-49109CRITICAL19 Aug 2025
Remote Code Execution in Apache Dolphinscheduler
48RISK
open
GitHub PoC
www-spam/CVE-2024-53900
CVE-2024-53900CRITICAL19 Aug 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RISK
open
GitHub PoC1
This is a rewritten exploit to work with php
CVE-2025-49113CRITICALunder attack19 Aug 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
CVE-2025-8088
CVE-2025-8088HIGHunder attackransomware19 Aug 2025
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack19 Aug 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
shoucheng3/x-stream__xstream_CVE-2013-7285_1-4-6
CVE-2013-728519 Aug 2025
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a rem
60RISK
open
VulnCheck XDB
infoleak
CVE-2024-53900CRITICAL19 Aug 2025
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
63RISK
open
GitHub PoC1
charanvoonna/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware19 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57791MEDIUM19 Aug 2025
Argument Injection Vulnerability in CommServe
33RISK
open
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57788MEDIUM19 Aug 2025
Unauthorized API Access Risk
28RISK
open
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57790HIGH19 Aug 2025
Path Traversal Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware19 Aug 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927
CVE-2025-29927CRITICAL19 Aug 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2014-873918 Aug 2025
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RISK
open
Exploit-DB
RiteCMS 3.0.0 - Reflected Cross Site Scripting (XSS)
CVE-2024-28623MEDIUMwebappsmultiple18 Aug 2025
RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec
48RISK
open
Exploit-DB
BigAnt Office Messenger 5.6.06 - SQL Injection
CVE-2024-54761MEDIUMwebappsmultiple18 Aug 2025
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
33RISK
open
GitHub PoC
shoucheng3/keycloak__keycloak_CVE-2022-3782_20-0-1
CVE-2022-3782CRITICAL18 Aug 2025
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs
48RISK
open
GitHub PoC5
CVE PoC
CVE-2013-3900MEDIUMunder attack18 Aug 2025
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
Exploit-DB
Tenda AC20 16.03.08.12 - Command Injection
CVE-2025-9090MEDIUMremotemultiple18 Aug 2025
Tenda AC20 Telnet Service telnet websFormDefine command injection
38RISK
open
GitHub PoC
CVE-2015-6967 PoC Exploit
CVE-2015-696718 Aug 2025
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open
VulnCheck XDB
local
CVE-2025-7771HIGH18 Aug 2025
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC3
This is an improved version of the CVE-2025-49132 proof of concept exploit.
CVE-2025-49132CRITICAL18 Aug 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
infoleak
CVE-2020-36708CRITICAL18 Aug 2025
Epsilon Framework Themes (Various Versions) - Function Injection
75RISK
open
VulnCheck XDB
local
CVE-2013-3900MEDIUMunder attack18 Aug 2025
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC3
Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing unauthenticated attackers to create administrator accounts.
CVE-2025-4334CRITICAL18 Aug 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISK
open
previouspage 282 / 2,698next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.