Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,003cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
81,003 exploits
GitHub PoC
alm6no5/CVE-2024-20767
CVE-2024-20767HIGHunder attack19 Jul 2025
ColdFusion | Improper Access Control (CWE-284)
100RISK
open
GitHub PoC2
Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploit sends crafted POST requests to trigger a crash and confirms the impact using ICMP (ping) checks.
CVE-2025-7795HIGH19 Jul 2025
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-41646CRITICAL19 Jul 2025
RevPi Webstatus application is vulnerable to an authentication bypass
75RISK
open
GitHub PoC
PoC for CVE-2024-47575
CVE-2024-47575CRITICALunder attack19 Jul 2025
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2
100RISK
open
GitHub PoC
r0otk3r/CVE-2025-31161
CVE-2025-31161CRITICALunder attackransomware19 Jul 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack18 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-47176HIGH18 Jul 2025
Microsoft Outlook Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack18 Jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
Local Privilege Escalation to Root via Sudo chroot in Linux
CVE-2025-32463CRITICALunder attack18 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2025-32463CRITICALunder attack18 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
Zenar CMS 9.3 suffers from an ​​unrestricted file upload vulnerability​​ in its file management module, allowing authenticated attackers (with minimal privileges) to upload arbitrary files, including malicious PHP scripts, to the web server.
CVE-2022-44136CRITICAL18 Jul 2025
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).
48RISK
open
GitHub PoC8
Exploit para explotar la vulnerabilidad CVE-2025-32463
CVE-2021-3156HIGHunder attack18 Jul 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC1
Joelp03/CVE-2025-49113
CVE-2025-49113CRITICALunder attack18 Jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack18 Jul 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC32
POC of CVE-2025-7783
CVE-2025-7783CRITICAL18 Jul 2025
Usage of unsafe random function in form-data for choosing boundary
48RISK
open
GitHub PoC
simplyfurious/CVE-2025-48384-submodule_test
CVE-2025-48384HIGHunder attack17 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC1
blindma1den/CVE-2025-47812
CVE-2025-47812CRITICALunder attack17 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
This is the exploit for the CVE-2025-32463
CVE-2025-32463CRITICALunder attack17 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
PoC of cve-2016-6210
CVE-2016-6210MEDIUM17 Jul 2025
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack17 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack17 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
admin-ping/CVE-2025-48384-RCE
CVE-2025-48384HIGHunder attack17 Jul 2025
Git allows arbitrary code execution through broken config quoting
71RISK
open
Exploit-DB
Keras 2.15 - Remote Code Execution (RCE)
CVE-2025-1550HIGHremotepython16 Jul 2025
Arbitrary Code Execution via Crafted Keras Config for Model Loading
41RISK
open
Exploit-DB
NodeJS 24.x - Path Traversal
CVE-2025-27210HIGHremotenodejs16 Jul 2025
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
46RISK
open
Exploit-DB
MikroTik RouterOS 7.19.1 - Reflected XSS
CVE-2025-6563MEDIUMremotemultiple16 Jul 2025
Cross-site scripting via dst parameter in RouterOS WiFi hotspot
33RISK
open
GitHub PoC
Floodnut/CVE-2025-32463
CVE-2025-32463CRITICALunder attack16 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
CVE-2025-34300CRITICAL16 Jul 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
85RISK
open
GitHub PoC
Kalidas-7/CVE-2019-9053
CVE-2019-905316 Jul 2025
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC5
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
CVE-2023-38408CRITICAL16 Jul 2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC
Exploit for php-cgi
CVE-2024-4577CRITICALunder attackransomware16 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
previouspage 300 / 2,701next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.