Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,243 exploits
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC92
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC12
PoC for SysAid PreAuth RCE Chain (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)
CVE-2025-2775CRITICALunder attack28 Mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISK
open
GitHub PoC
brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo
CVE-2024-23897CRITICALunder attackransomware28 Mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
N3xtGenH4cker/CVE-2020-0618_DETECTION
CVE-2020-0618CRITICALunder attack28 Mar 2025
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISK
open
GitHub PoC1
CVE-2025-30208 ViteVulnScanner
CVE-2025-30208MEDIUM28 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
CVE-2025-30208 | Vite脚本
CVE-2025-30208MEDIUM28 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC3
Create lab for CVE-2025-24813
CVE-2025-24813CRITICALunder attack28 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC3
CVE-2025-29927: Next.js Middleware Exploit
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
Exploit-DB
Progress Telerik Report Server 2024 Q1 (10.0.24.305) - Authentication Bypass
CVE-2024-4358CRITICALunder attackwebappsmultiple28 Mar 2025
Registration Authentication Bypass Vulnerability
100RISK
open
Exploit-DB
Sonatype Nexus Repository 3.53.0-01 - Path Traversal
CVE-2024-4956HIGHwebappsmultiple28 Mar 2025
Nexus Repository 3 - Path Traversal
61RISK
open
Exploit-DB
Litespeed Cache 6.5.0.1 - Authentication Bypass
CVE-2024-44000CRITICALwebappsphp28 Mar 2025
WordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
85RISK
open
GitHub PoC1
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL28 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC
This repository is for educational and research purposes.
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL28 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM28 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-2776CRITICALunder attack28 Mar 2025
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM28 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
Exploit-DB
CodeCanyon RISE CRM 3.7.0 - SQL Injection
CVE-2024-8945MEDIUMwebappsphp28 Mar 2025
CodeCanyon RISE Ultimate Project Manager save sql injection
38RISK
open
VulnCheck XDB
initial-access
CVE-2025-2775CRITICALunder attack28 Mar 2025
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-2777CRITICAL28 Mar 2025
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
85RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-30355HIGH28 Mar 2025
Synapse vulnerable to federation denial of service via malformed events
41RISK
open
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMunder attack27 Mar 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2017-5638CRITICALunder attackransomware27 Mar 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
Exploit-DB
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
CVE-2024-46528MEDIUMwebappsmultiple27 Mar 2025
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
33RISK
open
GitHub PoC2
Next.js CVE-2025-29927 Vulnerability Scanner
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
CVE-2025-30208 检测工具。python script && nuclei template
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC1
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
CVE-2019-9978MEDIUMunder attack27 Mar 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
previouspage 290 / 2,542next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.