Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,316cataloged exploits
34,835CVEs with public exploitation
24,695lab-tested
76,313 exploits
GitHub PoC1
iOS/macOS library that exploits CVE-2023-41991 for signing iOS applications.
CVE-2023-41991MEDIUMunder attack18 Mar 2025
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal
63RISK
open
GitHub PoC1
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
CVE-2024-56249CRITICAL18 Mar 2025
WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC7
Otsmane-Ahmed/cve-2025-29384-poc
CVE-2025-29384CRITICAL18 Mar 2025
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability
48RISK
open
VulnCheck XDB
local
CVE-2025-21333HIGHunder attack18 Mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack18 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
local
CVE-2025-21333HIGHunder attack18 Mar 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2023-4587817 Mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RISK
open
GitHub PoC
KillReal01/CVE-2023-4911
CVE-2023-4911HIGHunder attack17 Mar 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
GitHub PoC1
Jimmy01240397/CVE-2024-12641_12642_12645
CVE-2024-12641CRITICAL17 Mar 2025
Chunghwa Telecom TenderDocTransfer - Reflected Cross-site Scripting to RCE
48RISK
open
Metasploit600
Pandora FMS authenticated command injection leading to RCE via chromium_path or phantomjs_bin
CVE-2024-12971HIGH17 Mar 2025
QuickShell Authenticated Command Injection
48RISK
open
GitHub PoC
regantemudo/CVE-2024-25641-Exploit-for-Cacti-1.2.26
CVE-2024-25641CRITICAL17 Mar 2025
Cacti RCE vulnerability when importing packages
85RISK
open
GitHub PoC3
Nuclei Template CVE-2025–24813
CVE-2025-24813CRITICALunder attack17 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack17 Mar 2025
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
local
CVE-2023-4911HIGHunder attack17 Mar 2025
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-3459817 Mar 2025
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files
50RISK
open
GitHub PoC1
orilevy8/cve-2023-0386
CVE-2023-0386HIGHunder attack17 Mar 2025
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
client-side
CVE-2024-7014HIGH16 Mar 2025
Improper multimedia file attachment validation in Telegram for Android app
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL16 Mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM16 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC16
CVE-2025-24813利用工具
CVE-2025-24813CRITICALunder attack16 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-19781CRITICALunder attackransomware16 Mar 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
GitHub PoC2
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CVE-2023-30258CRITICAL16 Mar 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
GitHub PoC
DavidBr27/CVE-2013-3900-Remediation-Script
CVE-2013-3900MEDIUMunder attack16 Mar 2025
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC405
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
CVE-2025-24071MEDIUM16 Mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
CVE-2024-9047, wfu_file_downloader.php
CVE-2024-9047CRITICAL16 Mar 2025
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
85RISK
open
GitHub PoC
RCE, Citirx ADC and Gateway Directory Traversal
CVE-2019-19781CRITICALunder attackransomware16 Mar 2025
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack16 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack15 Mar 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC2
PoC - OpenSSL NPN Buffer Overread
CVE-2024-5535CRITICAL15 Mar 2025
SSL_select_next_proto buffer overread
48RISK
open
GitHub PoC
ishwardeepp/CVE-2025-22604-Cacti-RCE
CVE-2025-22604CRITICAL15 Mar 2025
Cacti has Authenticated RCE via multi-line SNMP responses
48RISK
open
previouspage 300 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.