Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,003cataloged exploits
37,620CVEs with public exploitation
24,695lab-tested
81,003 exploits
Exploit-DB
Microsoft Outlook - Remote Code Execution (RCE)
CVE-2025-47171MEDIUMremotewindows08 Jul 2025
Microsoft Outlook Remote Code Execution Vulnerability
33RISK
open
Exploit-DB
ScriptCase 9.12.006 (23) - Remote Command Execution (RCE)
CVE-2025-47228MEDIUMremotemultiple08 Jul 2025
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connecti
38RISK
open
GitHub PoC2
Authenticated RCE in Grafana (v11.0) via SQL Expressions - PoC Exploit
CVE-2024-9264CRITICAL07 Jul 2025
Grafana SQL Expressions allow for remote code execution
85RISK
open
GitHub PoC2
PwnToday/CVE-2025-6554
CVE-2025-6554HIGHunder attack07 Jul 2025
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
76RISK
open
GitHub PoC
Script Bash -- CVE-2021-3560
CVE-2021-3560HIGHunder attack07 Jul 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC3
ibrahmsql/CVE-2024-47773
CVE-2024-47773HIGH07 Jul 2025
Anonymous cache poisoning via XHR requests in Discourse
41RISK
open
GitHub PoC
Exploit for CVE-2025-47812 with custom psudo shell and robust error handling.
CVE-2025-47812CRITICALunder attack07 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
LibSSH authentification bypass
CVE-2018-10933CRITICAL07 Jul 2025
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RISK
open
GitHub PoC
POC
CVE-2025-24813CRITICALunder attack07 Jul 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC
Script Bash -- CVE-2021-3560
CVE-2021-3560HIGHunder attack07 Jul 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack07 Jul 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware07 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Exploit CVE-2025-24071
CVE-2025-24071MEDIUM07 Jul 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack07 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-48703CRITICALunder attack07 Jul 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack07 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC5
Docker PoC for CVE-2025-32462 & CVE-2025-32463 (sudo), based on Stratascale CRU research.
CVE-2025-32462LOW07 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC
r0otk3r/CVE-2024-4577
CVE-2024-4577CRITICALunder attackransomware07 Jul 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
local
CVE-2022-37969HIGHunder attackransomware06 Jul 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC9
A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC5
Proof of Concept for CVE-2025-32463 Local privilege escalation exploit targeting sudo -R on vulnerable Linux systems. For educational and authorized security testing only.
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-20281CRITICALunder attack06 Jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Ruby on Rails Web Console Exploit (CVE-2015-3224)
CVE-2015-322406 Jul 2025
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware06 Jul 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
Chocapikk/CVE-2025-32463-lab
CVE-2025-32463CRITICALunder attack06 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-55963MEDIUM06 Jul 2025
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the
45RISK
open
GitHub PoC1
An analysis and demonstration of the unauthenticated SQL Injection vulnerability (CVE-2022-3141) in ACS EDU 3rd Gen.
CVE-2022-314106 Jul 2025
Translatepress Multilinugal < 2.3.3 - Admin+ SQLi
23RISK
open
VulnCheck XDB
initial-access
CVE-2021-2564606 Jul 2025
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
previouspage 307 / 2,701next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.