Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
76,313 exploits
GitHub PoC15
Next.js PoC for CVE-2025-29927
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC4
Next.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。
CVE-2025-29927CRITICAL23 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC1
Writeup and POC for CVE-2022-23134
CVE-2022-23134LOWunder attack23 Mar 2025
Possible view of the setup pages by unauthenticated users if config file already exists
95RISK
open
Exploit-DB
Microsoft Windows - NTLM Hash Leak Malicious Windows Theme
CVE-2024-21320MEDIUMremotewindows22 Mar 2025
Windows Themes Spoofing Vulnerability
38RISK
open
GitHub PoC4
Next.js Middleware Authorization Bypass
CVE-2025-29927CRITICAL22 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC1
A PoC for CVE-2025-24813
CVE-2025-24813CRITICALunder attack22 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
Verify Next.js CVE-2025-29927 on Netlify not vulnerable
CVE-2025-29927CRITICAL22 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC1
A Bash script to enumerate valid SSH usernames using the CVE-2018-15473 vulnerability. It checks for valid usernames on an OpenSSH OpenSSH 7.2p2 server by analyzing authentication responses.
CVE-2018-15473MEDIUM22 Mar 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack22 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
CVE-2024-52375CRITICAL22 Mar 2025
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
48RISK
open
Exploit-DB
TeamPass 3.0.0.21 - SQL Injection
CVE-2023-1545HIGHwebappsphp22 Mar 2025
SQL Injection in nilsteampassnet/teampass
41RISK
open
GitHub PoC9
Otsmane-Ahmed/CVE-2025-2620-poc
CVE-2025-2620CRITICAL22 Mar 2025
D-Link DAP-1620 Authentication storage mod_graph_auth_uri_handler stack-based overflow
48RISK
open
GitHub PoC
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
CVE-2024-49653CRITICAL22 Mar 2025
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC2
WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability
CVE-2024-49668CRITICAL22 Mar 2025
WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability
48RISK
open
VulnCheck XDB
infoleak
CVE-2016-1092421 Mar 2025
The ebook-download plugin before 1.2 for WordPress has directory traversal.
43RISK
open
GitHub PoC2
WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
CVE-2025-23922CRITICAL21 Mar 2025
WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
Proof-of-concept for In invoke-ai/invokeai version v5.0.2 Arbitrary File Deletion.
CVE-2024-11042CRITICAL21 Mar 2025
Arbitrary File Delete in invoke-ai/invokeai
48RISK
open
GitHub PoC
wilss0n/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware21 Mar 2025
Argument Injection in PHP-CGI
100RISK
open
Metasploit300
Next.js Middleware Authorization Bypass Scanner
CVE-2025-29927CRITICAL21 Mar 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM21 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware21 Mar 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack21 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM21 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC4
CVE-2025-24813 Apache Tomcat RCE Proof of Concept (PoC)
CVE-2025-24813CRITICALunder attack21 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
POC for CVE-2025-24813 using Spring-Boot
CVE-2025-24813CRITICALunder attack20 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
Exploit-DB
JUX Real Estate 3.4.0 - SQL Injection
CVE-2025-2126MEDIUMwebappsphp20 Mar 2025
JoomlaUX JUX Real Estate GET Parameter realties sql injection
33RISK
open
GitHub PoC
PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)
CVE-2019-919320 Mar 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-4587820 Mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware20 Mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALunder attack20 Mar 2025
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RISK
open
previouspage 298 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.