Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,003cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
81,003 exploits
GitHub PoC2
Do you really think SharePoint is safe?
CVE-2025-53770CRITICALunder attackransomware24 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC5
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in on-premises Microsoft SharePoint Server (2016, 2019, Subscription Edition)
CVE-2025-53770CRITICALunder attackransomware23 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
CVE-2021-45046CRITICALunder attackransomware23 Jul 2025
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC1
A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over testing parameters, multiple attack patterns, and advanced monitoring capabilities.
CVE-2023-44487HIGHunder attack23 Jul 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
VulnCheck XDB
infoleak
CVE-2018-1171423 Jul 2025
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00
35RISK
open
GitHub PoC1
PoC exploit for CVE-2025-7766 – XXE vulnerability leading to potential RCE.
CVE-2025-7766HIGH23 Jul 2025
Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
41RISK
open
VulnCheck XDB
infoleak
CVE-2017-12637HIGHunder attack23 Jul 2025
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288923 Jul 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware23 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC8
Log4Shell / Log4J Payload - CVE-2021-45046 and CVE-2022-42889
CVE-2022-4288923 Jul 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC1
WordPress联系表单插件 - 未授权任意文件上传漏洞
CVE-2015-10137CRITICAL23 Jul 2025
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RISK
open
GitHub PoC4
How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX
CVE-2025-29774CRITICAL23 Jul 2025
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RISK
open
VulnCheck XDB
initial-access
CVE-2021-45046CRITICALunder attackransomware23 Jul 2025
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RISK
open
GitHub PoC
Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771
CVE-2025-53770CRITICALunder attackransomware23 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC5
CVE-2024-4577 Mass Scanner & Exploit Tool
CVE-2024-4577CRITICALunder attackransomware23 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32756CRITICALunder attack23 Jul 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
83RISK
open
GitHub PoC
wyyazjjl/CVE-2024-45195
CVE-2024-45195CRITICALunder attack23 Jul 2025
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
100RISK
open
GitHub PoC
Skac44/CVE-2024-38063
CVE-2024-38063CRITICAL23 Jul 2025
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC31
Integer overflow in FreeType software, which also affects Chrome
CVE-2025-27363HIGHunder attack23 Jul 2025
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RISK
open
GitHub PoC1
Nuclei template to detect CVE-2024-6387. All latest patched versions are excluded.
CVE-2024-6387HIGH23 Jul 2025
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack23 Jul 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
VulnCheck XDB
client-side
CVE-2025-27363HIGHunder attack23 Jul 2025
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RISK
open
GitHub PoC
Proof-of-concept LFI Scanner: Automated detection of /etc/passwd exposures via directory traversal and regex matching.
CVE-2017-12637HIGHunder attack23 Jul 2025
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Se
100RISK
open
GitHub PoC
shan0ar/cve-2025-32756
CVE-2025-32756CRITICALunder attack23 Jul 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
83RISK
open
GitHub PoC5
PoC for CVE-2025-5777 – Auth Bypass and RCE in Trend Micro Apex Central
CVE-2025-5777CRITICALunder attackransomware23 Jul 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
client-side
CVE-2024-4947CRITICALunder attack23 Jul 2025
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside
83RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware23 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-53770CRITICALunder attackransomware23 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware23 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL23 Jul 2025
Authorization Bypass in Next.js Middleware
85RISK
open
previouspage 296 / 2,701next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.