Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
Exploit-DB
MoziloCMS 3.0 - Remote Code Execution (RCE)
CVE-2024-44871HIGHwebappsphp27 Mar 2025
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute a
46RISK
open
Exploit-DB
KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR)
CVE-2024-46528MEDIUMwebappsmultiple27 Mar 2025
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
33RISK
open
Exploit-DB
X2CRM 8.5 - Stored Cross-Site Scripting (XSS)
CVE-2024-48120MEDIUMwebappsphp27 Mar 2025
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma
33RISK
open
GitHub PoC
CVE-2025-30208 检测工具。python script && nuclei template
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
Vite-CVE-2025-30208动态检测脚本,支持默认路径,自定义路径动态检测
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC25
A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes
CVE-2025-24071MEDIUM27 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC4
This exploit is for educational and ethical security testing purposes only. The use of this exploit against targets without prior mutual consent is illegal, and the developer disclaims any liability for misuse or damage caused by this exploit.
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC1
rubbxalc/CVE-2025-24071
CVE-2025-24071MEDIUM27 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC10
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC1
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
CVE-2019-9978MEDIUMunder attack27 Mar 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC35
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
CVE-2025-24071MEDIUM27 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted AdmissionReview request to simulate a potential exploit path from CVE-2025-1974 and checks for signs of misinterpreted annotations in controller logs.
CVE-2025-1974CRITICAL27 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC
IngressNightmare (CVE-2025-1974)
CVE-2025-1974CRITICAL27 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC3
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
CVE-2025-2294CRITICAL27 Mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC1
python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC1
> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC2
next.js CVE-2025-29927 vulnerability exploit
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para detectar accesos no autorizados.
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC2
Next.js CVE-2025-29927 Vulnerability Scanner
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
liemkaka/CVE-2018-9206
CVE-2018-920627 Mar 2025
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.
CVE-2017-5638CRITICALunder attackransomware27 Mar 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
client-side
CVE-2025-30349HIGH27 Mar 2025
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account take
53RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL27 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
previouspage 293 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.