Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,003cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
81,003 exploits
GitHub PoC2
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, leveraging directory traversal for remote code execution.
CVE-2025-54769HIGH30 Jul 2025
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41RISK
open
GitHub PoC1
🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked data.
CVE-2025-14847HIGHunder attack30 Jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
CitrixBleed 2 NetScaler honeypot logs
CVE-2025-5777CRITICALunder attackransomware30 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack30 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
Technical Details and Exploit for CVE-2025-50472
CVE-2025-50472CRITICAL30 Jul 2025
The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untruste
48RISK
open
GitHub PoC21
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-29824HIGHunder attackransomware30 Jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
rgvillanueva28/vulnbox-easy-CVE-2025-29927
CVE-2025-29927CRITICAL30 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
local
CVE-2023-22809HIGH30 Jul 2025
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RISK
open
VulnCheck XDB
client-side
CVE-2023-2533HIGHunder attack30 Jul 2025
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF
76RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack30 Jul 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Real-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.
CVE-2017-5638CRITICALunder attackransomware30 Jul 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-1675HIGHunder attackransomware29 Jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware29 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL29 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC1
Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original Exploit‑DB PoC for educational and authorized testing purposes only.
CVE-2021-43857CRITICAL29 Jul 2025
Gerapy may contain remote code execution vulnerability
60RISK
open
GitHub PoC4
Immersive-Labs-Sec/SharePoint-CVE-2025-53770-POC
CVE-2025-53770CRITICALunder attackransomware29 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
→ poc for CVE-2025-29927
CVE-2025-29927CRITICAL29 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC2
CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit
CVE-2025-32463CRITICALunder attack29 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
classic130/CVE-2024-23897-Jenkins-4.441
CVE-2024-23897CRITICALunder attackransomware29 Jul 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
Ai相关
CVE-2025-54381CRITICAL29 Jul 2025
BentoML is Vulnerable to an SSRF Attack Through File Upload Processing
53RISK
open
GitHub PoC1
DLL00P/CVE-2021-1675
CVE-2021-1675HIGHunder attackransomware29 Jul 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack29 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack28 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL28 Jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC1
The vulnerability was found by Rich Mirch. More details on it here: https://cxsecurity.com/issue/WLB-2025070022
CVE-2025-32462LOW28 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC
r0otk3r/CVE-2025-2294
CVE-2025-2294CRITICAL28 Jul 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
Exploit-DB
Linux PAM Environment - Variable Injection Local Privilege Escalation
CVE-2025-6018HIGHlocallinux28 Jul 2025
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open
GitHub PoC
r3xbugbounty/CVE-2025-53770
CVE-2025-53770CRITICALunder attackransomware28 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware28 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware28 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
previouspage 293 / 2,701next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.