Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
81,064 exploits
VulnCheck XDB
local
CVE-2020-1048HIGH23 Jun 2025
Windows Print Spooler Elevation of Privilege Vulnerability
61RISK
open
GitHub PoC
CVE-2025-3248
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC7
Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC3
Mass-CVE-2025-3248
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC2
Exploit (C) CVE-2024-4577 on PHP CGI
CVE-2024-4577CRITICALunder attackransomware23 Jun 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC4
Pterodactyl翼龙面板CVE-2025-49132批量检测☝️🤓
CVE-2025-49132CRITICAL23 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware23 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
cuerv0x/CVE-2015-6967
CVE-2015-696723 Jun 2025
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL23 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-49132CRITICAL23 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC1
CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework
CVE-2023-33538HIGHunder attack23 Jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open
GitHub PoC2
Check a list of Pterodactyl panels for vulnerabilities from a file.
CVE-2025-49132CRITICAL23 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-1562CRITICAL22 Jun 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-1562CRITICAL22 Jun 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISK
open
GitHub PoC
CVE 2018-9035: CSV Injection in Wordpress with plugin Contact Form 7 to Database Extension 2.10.3
CVE-2018-903522 Jun 2025
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RISK
open
GitHub PoC1
sendINUX/CVE-2021-22600__DirtyPagetable
CVE-2021-22600MEDIUMunder attack22 Jun 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISK
open
VulnCheck XDB
local
CVE-2021-22600MEDIUMunder attack22 Jun 2025
Double Free in net/packet/af_packet.c leading to priviledge escalation
63RISK
open
GitHub PoC17
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
CVE-2025-49132CRITICAL22 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
infoleak
CVE-2025-49132CRITICAL22 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC1
Python Exploit for TP-Link TL-WR940N/TL-WR841N Command Injection Vulnerability
CVE-2023-33538HIGHunder attack22 Jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-33538HIGHunder attack22 Jun 2025
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerabili
83RISK
open
VulnCheck XDB
initial-access
CVE-2025-3515HIGH22 Jun 2025
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
56RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware22 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware22 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
gmh5225/CVE-2025-1562
CVE-2025-1562CRITICAL22 Jun 2025
Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation
63RISK
open
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL21 Jun 2025
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
tomcat CVE-2025-24813 反序列化RCE环境
CVE-2025-24813CRITICALunder attack21 Jun 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack21 Jun 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC4
mbanyamer/PX4-Military-UAV-Autopilot-1.12.3-Stack-Buffer-Overflow-Exploit-CVE-2025-5640-
CVE-2025-5640MEDIUM21 Jun 2025
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISK
open
previouspage 316 / 2,703next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.