Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,107 exploits
GitHub PoC
Sornphut/CVE-2023-7028-GitLab
CVE-2023-7028CRITICALunder attack29 Mar 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
Exploit-DB
CodeCanyon RISE CRM 3.7.0 - SQL Injection
CVE-2024-8945MEDIUMwebappsphp28 Mar 2025
CodeCanyon RISE Ultimate Project Manager save sql injection
38RISK
open
GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
CVE-2024-23897CRITICALunder attackransomware28 Mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-2777CRITICAL28 Mar 2025
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-2776CRITICALunder attack28 Mar 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-2775CRITICALunder attack28 Mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM28 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM28 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
CVE-2025-2775CRITICALunder attack28 Mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISK
open
GitHub PoC1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL28 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
Exploit-DB
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
CVE-2024-4358CRITICALunder attackwebappsmultiple28 Mar 2025
Registration Authentication Bypass Vulnerability
100RISK
open
GitHub PoC92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC3
CVE-2025-29927: Next.js Middleware Exploit
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
This repository is for educational and research purposes.
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC3
Create lab for CVE-2025-24813
CVE-2025-24813CRITICALunder attack28 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Exploit-DB
Litespeed Cache 6.5.0.1 - Authentication Bypass
CVE-2024-44000CRITICALwebappsphp28 Mar 2025
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
Exploit-DB
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
CVE-2024-4956HIGHwebappsmultiple28 Mar 2025
Nexus Repository 3 - Path Traversal
61RISK
open
Exploit-DB
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
CVE-2024-23692CRITICALunder attackwebappstypescript28 Mar 2025
Rejetto HTTP File Server 2.3m Unauthenticated RCE
100RISK
open
GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
CVE-2020-0618CRITICALunder attack28 Mar 2025
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open
GitHub PoC
CVE-2025-30208 | Vite脚本
CVE-2025-30208MEDIUM28 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC1
CVE-2025-30208 ViteVulnScanner
CVE-2025-30208MEDIUM28 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-30355HIGH28 Mar 2025
Synapse vulnerable to federation denial of service via malformed events
41RISK
open
GitHub PoC
Heimd411/CVE-2025-29927-PoC
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC7
CVE-2025-29927에 대한 설명 및 리서치
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
Exploit-DB
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
CVE-2024-46528MEDIUMwebappsmultiple27 Mar 2025
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
33RISK
open
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2021-44228CRITICALunder attackransomware27 Mar 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL27 Mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC1
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
CVE-2019-9978MEDIUMunder attack27 Mar 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
previouspage 289 / 2,537next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.