Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
81,064 exploits
GitHub PoC1
obscura-cert/CVE-2025-33073
CVE-2025-33073HIGHunder attack28 Jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC1
POC for PDF JS' CVE-2024-4367 vuln
CVE-2024-4367MEDIUM28 Jun 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
aninfosec/CVE-2024-43425-Poc
CVE-2024-43425HIGH28 Jun 2025
Moodle: remote code execution via calculated question types
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL28 Jun 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
GitHub PoC2
POC for PDF JS' CVE-2024-4367 vuln
CVE-2024-4367MEDIUM28 Jun 2025
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHunder attack28 Jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC3
Proof-of-concept and analysis for CVE-2025-32711
CVE-2025-32711CRITICAL27 Jun 2025
M365 Copilot Information Disclosure Vulnerability
48RISK
open
GitHub PoC10
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
CVE-2025-30208MEDIUM27 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC
Escala de privilegios con CVE-2010-5195
CVE-2010-519527 Jun 2025
Untrusted search path vulnerability in Roxio MyDVD 9 allows local users to gain privileges via a Trojan horse HomeUtils9
23RISK
open
GitHub PoC21
Unauthenticated Python PoC for CVE-2025-20281 RCE against ISE ERS API
CVE-2025-20281CRITICALunder attack27 Jun 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Security analysis project: Real-world CVE breakdown
CVE-2024-3094CRITICAL27 Jun 2025
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-20281CRITICALunder attack27 Jun 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open
Metasploit300
Marvell QConvergeConsole Path Traversal (CVE-2025-6793)
CVE-2025-6793CRITICAL27 Jun 2025
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
48RISK
open
Metasploit600
PandoraFMS Netflow Authenticated Remote Code Execution
CVE-2025-5306HIGH27 Jun 2025
Command Injection in Netflow path
48RISK
open
GitHub PoC
The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to extract potentially sensitive information from server memory over the TLS protocol.
CVE-2014-0160HIGHunder attack27 Jun 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC17
speinador/CVE-2025-6218_WinRAR
CVE-2025-6218HIGHunder attack27 Jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
VulnCheck XDB
client-side
CVE-2025-6218HIGHunder attack27 Jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
loganpkinfosec/CVE-2020-7378
CVE-2020-7378CRITICAL27 Jun 2025
CRIXP OpenCRX Unverified Password Change
48RISK
open
Exploit-DB
freeSSHd 1.0.9 - Denial of Service (DoS)
CVE-2024-0723MEDIUMremotewindows26 Jun 2025
freeSSHd denial of service
33RISK
open
Exploit-DB
Sitecore 10.4 - Remote Code Execution (RCE)
CVE-2025-27218MEDIUMwebappsmultiple26 Jun 2025
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RISK
open
GitHub PoC4
Remote Code execution in CentOS web panel
CVE-2025-48703CRITICALunder attack26 Jun 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
Exploit-DB
PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
CVE-2025-5640MEDIUMremotemultiple26 Jun 2025
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISK
open
GitHub PoC7
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
CVE-2025-4334CRITICAL26 Jun 2025
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
63RISK
open
GitHub PoC5
Script para determinar si Citrix es vulnerable al CVE-2025-6543
CVE-2025-6543CRITICALunder attack26 Jun 2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service
83RISK
open
Exploit-DB
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
CVE-2024-57708MEDIUMremotelinux26 Jun 2025
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISK
open
Exploit-DB
Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
CVE-2025-49132CRITICALwebappsmultiple26 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
Exploit-DB
McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
CVE-2022-1257MEDIUMremotemultiple26 Jun 2025
Improper Verification of Cryptographic Signature by McAfee Agent
33RISK
open
VulnCheck XDB
local
CVE-2025-21756HIGH26 Jun 2025
vsock: Keep the binding until socket destruction
41RISK
open
Exploit-DB
Microsoft Excel 2024 Use after free - Remote Code Execution (RCE)
CVE-2025-47165HIGHremotewindows26 Jun 2025
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
previouspage 314 / 2,703next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.