Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,063cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
81,063 exploits
GitHub PoC
DirtyPipe (CVE-2022-0847) exploit written in Rust
CVE-2022-0847HIGHunder attack01 Jul 2025
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack01 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC1
Proof of concept of CVE-2025-20282, the perfect 10.
CVE-2025-20282CRITICAL01 Jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
68RISK
open
GitHub PoC
POC script for CVE-2025-32462 a vulnerability in sudo
CVE-2025-32462LOW01 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
GitHub PoC9
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation
CVE-2025-6934CRITICAL01 Jul 2025
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
GitHub PoC10
End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.
CVE-2025-32463CRITICALunder attack01 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC1
4f-kira/CVE-2025-32463
CVE-2025-32463CRITICALunder attack01 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC54
Wing FTP Server Remote Code Execution (RCE) Exploit (CVE-2025-47812)
CVE-2025-47812CRITICALunder attack01 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC1
Detects Apache HTTP Server path traversal vulnerabilities (CVE-2021-41773, CVE-2021-42013) by checking for exposure of /etc/passwd through various traversal techniques.
CVE-2021-41773HIGHunder attackransomware01 Jul 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC13
Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.
CVE-2025-47812CRITICALunder attack01 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
Simulação educacional de exploração de falha em dispositivos IoT com base no CVE-2017-17761
CVE-2017-1776130 Jun 2025
An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 130
23RISK
open
GitHub PoC17
详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件
CVE-2025-5777CRITICALunder attackransomware30 Jun 2025
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
Metasploit300
Sudo Chroot 1.9.17 Privilege Escalation
CVE-2025-32463CRITICALunder attack30 Jun 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
Metasploit600
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
CVE-2025-47812CRITICALunder attack30 Jun 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
Citrix Bleed 2 PoC
CVE-2025-6543CRITICALunder attack30 Jun 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
83RISK
open
GitHub PoC2
This Python script is a Proof-of-Concept (PoC) scanner for detecting the vulnerability CVE-2024-40898, which affects Apache HTTP Server’s SSL certificate validation.
CVE-2024-40898CRITICAL30 Jun 2025
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
48RISK
open
VulnCheck XDB
initial-access
CVE-2020-1198430 Jun 2025
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
60RISK
open
GitHub PoC13
A simple proof of concept for WinRAR Path Traversal | RCE | CVE-2025-6218
CVE-2025-6218HIGHunder attack29 Jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
Exploit Code for CVE-2024-39930 gogs ssh server RCE
CVE-2024-39930CRITICAL29 Jun 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISK
open
VulnCheck XDB
client-side
CVE-2025-4664MEDIUM29 Jun 2025
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro
33RISK
open
VulnCheck XDB
info-leak
CVE-2016-20016CRITICAL29 Jun 2025
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RISK
open
VulnCheck XDB
initial-access
CVE-2024-54085CRITICALunder attack29 Jun 2025
Redfish Authentication Bypass
90RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM29 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL29 Jun 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH29 Jun 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
client-side
CVE-2025-6218HIGHunder attack29 Jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
GitHub PoC1
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
CVE-2025-30208MEDIUM29 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC2
Just poc for CVE 2024-54085
CVE-2024-54085CRITICALunder attack29 Jun 2025
Redfish Authentication Bypass
90RISK
open
GitHub PoC1
POC for PDF JS' CVE-2024-4367 vuln
CVE-2024-4367MEDIUM28 Jun 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC1
obscura-cert/CVE-2025-33073
CVE-2025-33073HIGHunder attack28 Jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
previouspage 313 / 2,703next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.