Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
GitHub PoC10
CVE-2025-30208-EXP 任意文件读取
CVE-2025-30208MEDIUM26 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
Exploit-DB
NVIDIA Container Toolkit 1.16.1 - Time-of-check Time-of-Use (TOCTOU)
CVE-2024-0132CRITICALlocallinux26 Mar 2025
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de
60RISK
open
GitHub PoC2
A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC8
Poc for Ingress RCE
CVE-2025-1974CRITICAL26 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC8
This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.
CVE-2025-29927CRITICAL26 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC248
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
CVE-2025-1097HIGH26 Mar 2025
ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
68RISK
open
VulnCheck XDB
infoleak
CVE-2025-30567HIGH26 Mar 2025
WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability
56RISK
open
GitHub PoC1
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
CVE-2024-12252CRITICAL26 Mar 2025
SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)
48RISK
open
GitHub PoC
A root exploit for CVE-2022-0847 (Dirty Pipe)
CVE-2022-0847HIGHunder attack25 Mar 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC2
CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw allows attackers to bypass authorization checks implemented in Next.js middleware, potentially granting unauthorized access to sensitive areas of an application, such as admin pages or user dashboards.
CVE-2025-29972CRITICAL25 Mar 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RISK
open
Metasploit600
Appsmith RCE
CVE-2024-55964CRITICAL25 Mar 2025
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea
43RISK
open
GitHub PoC
Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload
CVE-2024-31114CRITICAL25 Mar 2025
WordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL25 Mar 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
GitHub PoC
CVE-2025-22912
CVE-2025-22912CRITICAL25 Mar 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
48RISK
open
GitHub PoC3
script to check cve "CVE-2025-29927" while waiting to add it to HExHTTP
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC1
PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios d'attaque, analyse des risques et serveur Express.js de test.
CVE-2024-4367MEDIUM25 Mar 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
yanmarques/CVE-2025-1974
CVE-2025-1974CRITICAL25 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC
The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.
CVE-2024-21413CRITICALunder attack25 Mar 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC53
yoshino-s/CVE-2025-1974
CVE-2025-1974CRITICAL25 Mar 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC
maronnjapan/claude-create-CVE-2025-29927
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Critical vulnerability in next.js : Bypass middleware authentication
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
somatrasss/CVE-2025-29306
CVE-2025-29306CRITICAL25 Mar 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
GitHub PoC
0xPb1/Next.js-CVE-2025-29927
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC2
PowerShell script to test if a web app is vulnerable to CVE-2025-29927
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC5
PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
jeymo092/cve-2025-29927
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC9
Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
0xcucumbersalad/cve-2025-29927
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
0xPThree/next.js_cve-2025-29927
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL25 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
previouspage 295 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.