Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,002cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
81,002 exploits
GitHub PoC
Webmin CVE-2022-0824 增强版漏洞利用工具 - 支持命令执行和反向Shell双模式
CVE-2022-0824HIGH05 Aug 2025
Improper Access Control to Remote Code Execution in webmin/webmin
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-7028CRITICALunder attack05 Aug 2025
Weak Password Recovery Mechanism for Forgotten Password in GitLab
100RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack05 Aug 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack04 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC1
beishanxueyuan/CVE-2025-48384-test
CVE-2025-48384HIGHunder attack04 Aug 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC
For Home Lab and Educational Purpose only not intended for any Harmful intenstions purely for educational purpose
CVE-2018-7600CRITICALunder attackransomware04 Aug 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
CVE-2020-0688HIGHunder attackransomware04 Aug 2025
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC
CVE-2013-3900 WinVerifyTrust Signature
CVE-2013-3900MEDIUMunder attack04 Aug 2025
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
Metasploit600
WordPress StoryChief Plugin Unauthenticated RCE
CVE-2025-7441CRITICAL04 Aug 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Template Import
CVE-2026-32985CRITICAL04 Aug 2025
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
63RISK
open
GitHub PoC22
PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.
CVE-2025-24893CRITICALunder attack04 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-7340CRITICAL04 Aug 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RISK
open
VulnCheck XDB
infoleak
CVE-2021-44228CRITICALunder attackransomware04 Aug 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
A simple Log4j PoC written in Go
CVE-2021-44228CRITICALunder attackransomware04 Aug 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHunder attackransomware04 Aug 2025
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware04 Aug 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC17
CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper handling of Groovy expressions in the SolrSearch macro.
CVE-2025-24893CRITICALunder attack04 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack04 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack04 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
Kai-One001/WordPress-HT-Contact-CVE-2025-7340-RCE
CVE-2025-7340CRITICAL04 Aug 2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
48RISK
open
GitHub PoC5
Tribell Edge Sandbox Escape - PoCs of Edge's legacy vulnerabilities BadgeUpdateManager / TileFlyoutUpdateManager / ToastNotificationManager to exploit cross-boundary XmlDocument sharing and escape Edge’s LPAC sandbox (CVE-2019-0555).
CVE-2019-055503 Aug 2025
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape
23RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack03 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-2771CRITICAL03 Aug 2025
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack03 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack03 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack03 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC5
this is a poc for the CVE-2025-24893
CVE-2025-24893CRITICALunder attack03 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
Exploit-DB
Microsoft Virtual Hard Disk (VHDX) 11 - Remote Code Execution (RCE)
CVE-2025-49683HIGHlocalwindows03 Aug 2025
Microsoft Virtual Hard Disk Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
dhiaZnaidi/CVE-2025-24893-PoC
CVE-2025-24893CRITICALunder attack03 Aug 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
Exploit-DB
Swagger UI 1.0.3 - Cross-Site Scripting (XSS)
CVE-2025-8191MEDIUMremotemultiple03 Aug 2025
macrozheng mall Swagger UI index.html cross site scripting
33RISK
open
previouspage 290 / 2,701next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.