Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
81,064 exploits
Exploit-DB
freeSSHd 1.0.9 - Denial of Service (DoS)
CVE-2024-0723MEDIUMremotewindows26 Jun 2025
freeSSHd denial of service
33RISK
open
Exploit-DB
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
CVE-2024-57708MEDIUMremotelinux26 Jun 2025
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISK
open
VulnCheck XDB
local
CVE-2019-573625 Jun 2025
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware25 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
hdgokani/CVE-2018-1273
CVE-2018-1273CRITICALunder attackransomware25 Jun 2025
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-48828CRITICAL25 Jun 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM25 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2018-1273CRITICALunder attackransomware25 Jun 2025
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-10924CRITICAL25 Jun 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVE-2025-3248CRITICALunder attackransomware25 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
Poc - CVE-2025-49132
CVE-2025-49132CRITICAL25 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
C-based PoC for CVE-2019-5736
CVE-2019-573625 Jun 2025
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.9.2 CVE-2025-47577 PoC
CVE-2025-47577CRITICAL25 Jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
63RISK
open
Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
CVE-2024-51978CRITICAL25 Jun 2025
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RISK
open
GitHub PoC
Batch RCE scanner for vulnerable vBulletin instances using replaceAdTemplate exploit.
CVE-2025-48828CRITICAL25 Jun 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISK
open
VulnCheck XDB
initial-access
CVE-2024-43917CRITICAL25 Jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open
Metasploit300
Multiple Brother devices authentication bypass via default administrator password generation
CVE-2024-51977MEDIUM25 Jun 2025
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RISK
open
GitHub PoC3
ademto/wordpress-cve-2024-10924-pentest
CVE-2024-10924CRITICAL25 Jun 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-49132CRITICAL25 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware25 Jun 2025
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones para su uso en entornos controlados.
CVE-2016-5195HIGHunder attack25 Jun 2025
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
TI WooCommerce Wishlist (WordPress plugin) <= 2.8.2 CVE-2024-43917 PoC
CVE-2024-43917CRITICAL25 Jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open
GitHub PoC
Rust Macros No Recoil Guide 🚀 Boost Aim Like a Pro in C and Python
CVE-2025-0411HIGHunder attack24 Jun 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL24 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥
CVE-2025-4322CRITICAL24 Jun 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISK
open
GitHub PoC5
PoCs for CVE-2025-49132
CVE-2025-49132CRITICAL24 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
A script is a PoC for CVE-2022-1257, a vulnerability in the McAfee Agent (Trellix Agent) when working with it's database. The vulnerability allows attackers to retrieve and decrypt credentials from the McAfee Agent database file (`ma.db`) due to improper encryption key handling.
CVE-2022-1257MEDIUM24 Jun 2025
Improper Verification of Cryptographic Signature by McAfee Agent
33RISK
open
GitHub PoC3
Mass-CVE-2025-3248
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC2
Exploit (C) CVE-2024-4577 on PHP CGI
CVE-2024-4577CRITICALunder attackransomware23 Jun 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC1
CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework
CVE-2023-33538HIGHunder attack23 Jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open
previouspage 315 / 2,703next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.