Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,496cataloged exploits
34,964CVEs with public exploitation
24,695lab-tested
76,313 exploits
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHunder attack04 Mar 2025
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-8963CRITICALunder attack04 Mar 2025
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func
100RISK
open
GitHub PoC
GazettEl/CVE-2020-17519
CVE-2020-17519CRITICALunder attack02 Mar 2025
Apache Flink directory traversal attack: reading remote files through the REST API
100RISK
open
GitHub PoC3
Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.
CVE-2020-35391CRITICAL02 Mar 2025
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open
VulnCheck XDB
infoleak
CVE-2020-35391CRITICAL02 Mar 2025
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_pas
60RISK
open
GitHub PoC
Project on CVE-2022-30190 exploitation and mitigation strategies
CVE-2022-30190HIGHunder attackransomware02 Mar 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
Metasploit300
Xorcom CompletePBX Authenticated File Disclosure via Backup Download
CVE-2025-2292MEDIUM02 Mar 2025
Xorcom CompletePBX <= 5.2.35 Authenticated File Disclosure
28RISK
open
Metasploit300
Xorcom CompletePBX Arbitrary File Read and Deletion via systemDataFileName
CVE-2025-30005HIGH02 Mar 2025
Xorcom CompletePBX <= 5.2.35 Authenticated Path Traversal & File Deletion
36RISK
open
Metasploit600
Xorcom CompletePBX Authenticated Command Injection via Task Scheduler
CVE-2025-30004HIGH02 Mar 2025
Xorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection
36RISK
open
VulnCheck XDB
local
CVE-2023-32434HIGHunder attack01 Mar 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISK
open
VulnCheck XDB
initial-access
CVE-2019-1003030CRITICALunder attack01 Mar 2025
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open
GitHub PoC
CVE-2019-18935: Remote Code Execution
CVE-2019-18935CRITICALunder attackransomware01 Mar 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC129
Deterministic kernel exploit based on CVE-2023-32434.
CVE-2023-32434HIGHunder attack01 Mar 2025
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11
83RISK
open
GitHub PoC1
overgrowncarrot1/CVE-2019-1003030
CVE-2019-1003030CRITICALunder attack01 Mar 2025
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open
GitHub PoC
CVE-2023-1545-POC with python
CVE-2023-1545HIGH01 Mar 2025
SQL Injection in nilsteampassnet/teampass
41RISK
open
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALunder attackransomware01 Mar 2025
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RISK
open
GitHub PoC4
Mautic < 5.2.3 Authenticated RCE
CVE-2024-47051CRITICAL28 Feb 2025
Remote Code Execution & File Deletion in Asset Uploads
48RISK
open
GitHub PoC1
skrkcb2/CVE-2023-46604
CVE-2023-46604CRITICALunder attackransomware27 Feb 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware27 Feb 2025
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-21333HIGHunder attack27 Feb 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC232
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
CVE-2025-21333HIGHunder attack27 Feb 2025
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
cojoben/CVE-2018-13382
CVE-2018-13382CRITICALunder attackransomware26 Feb 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
GitHub PoC
monjheta/CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware26 Feb 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC7
CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can exploit this flaw to execute arbitrary commands on the server, leading to a full system compromise.
CVE-2025-26264HIGH26 Feb 2025
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili
46RISK
open
VulnCheck XDB
infoleak
CVE-2024-24919HIGHunder attackransomware26 Feb 2025
Information disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack26 Feb 2025
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALunder attackransomware26 Feb 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-13382CRITICALunder attackransomware26 Feb 2025
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RISK
open
GitHub PoC6
CVE-2025-26263 - GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less, is vulnerable to credentials disclosure due to improper memory handling in the ASManagerService.exe process.
CVE-2025-26263MEDIUM26 Feb 2025
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RISK
open
GitHub PoC
SpiX-7/CVE-2024-24919-POC
CVE-2024-24919HIGHunder attackransomware26 Feb 2025
Information disclosure
100RISK
open
previouspage 304 / 2,544next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.