Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
A custom Python-based proof-of-concept (PoC) exploit targeting Text4Shell (CVE-2022-42889), a critical remote code execution vulnerability in Apache Commons Text versions < 1.10.
CVE-2022-4288924 Mar 2025
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
Metasploit600
WP User Registration and Membership Unauthenticated Privilege Escalation (CVE-2025-2563)
CVE-2025-2563HIGH24 Mar 2025
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
68RISK
open
GitHub PoC3
CVE-2025-29927 Proof of Concept
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC5
Demo for Next.js middleware bypass - CVE-2025-29927
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC4
CVE-2025-29927 Exploit Checker
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC6
CVE-2025-29927 lab
CVE-2025-29927CRITICAL24 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC9
Authorization Bypass in Next.js Middleware
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
client-side
CVE-2025-27363HIGHunder attack23 Mar 2025
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-23897CRITICALunder attackransomware23 Mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-23134LOWunder attack23 Mar 2025
Possible view of the setup pages by unauthenticated users if config file already exists
95RISK
open
GitHub PoC4
Next.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC101
CVE-2025-29927 Proof of Concept
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC14
lirantal/vulnerable-nextjs-14-CVE-2025-29927
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Jenkins RCE Arbitrary File Read CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware23 Mar 2025
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC38
zhuowei/CVE-2025-27363-proof-of-concept
CVE-2025-27363HIGHunder attack23 Mar 2025
An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when
76RISK
open
GitHub PoC1
Writeup and POC for CVE-2022-23134
CVE-2022-23134LOWunder attack23 Mar 2025
Possible view of the setup pages by unauthenticated users if config file already exists
95RISK
open
GitHub PoC
ticofookfook/poc-nextjs-CVE-2025-29927
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
previouspage 297 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.