Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
81,064 exploits
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL21 Jun 2025
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2024-35250HIGHunder attack21 Jun 2025
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
91RISK
open
GitHub PoC
tomcat CVE-2025-24813 反序列化RCE环境
CVE-2025-24813CRITICALunder attack21 Jun 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC4
mbanyamer/PX4-Military-UAV-Autopilot-1.12.3-Stack-Buffer-Overflow-Exploit-CVE-2025-5640-
CVE-2025-5640MEDIUM21 Jun 2025
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISK
open
GitHub PoC
CVE-2021-44228 Vulnerability Reproduction Environment CVE-2021-44228 漏洞复现环境
CVE-2021-44228CRITICALunder attackransomware21 Jun 2025
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
punitdarji/Grafana-cve-2025-4123
CVE-2025-4123HIGH21 Jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack20 Jun 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
Exploit-DB
Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)
CVE-2025-47957HIGHlocalwindows20 Jun 2025
Microsoft Word Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
typicalsmc/CVE-2025-49132-PoC
CVE-2025-49132CRITICAL20 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
Exploit-DBVexDay Proof
Ingress-NGINX 4.11.0 - Remote Code Execution (RCE)
CVE-2025-1974CRITICALremotemultiple20 Jun 2025
ingress-nginx admission controller RCE escalation
85RISK
open
Exploit-DB
FortiOS SSL-VPN 7.4.4 - Insufficient Session Expiration & Cookie Reuse
CVE-2024-50562MEDIUMremotemultiple20 Jun 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RISK
open
GitHub PoC
Rejetto HttpFileServer 2.3.x - Remote Command Execution (RevShell)
CVE-2014-6287CRITICALunder attack20 Jun 2025
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH20 Jun 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
GitHub PoC
CVE-2024-50562 is a session management vulnerability in Fortinet SSL-VPN portals
CVE-2024-50562MEDIUM20 Jun 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RISK
open
GitHub PoC
This is a proof-of-concept Metasploit module exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote code execution via a crafted UDP packet.
CVE-2015-157820 Jun 2025
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISK
open
GitHub PoC
Tiny File Manager <= 2.4.6 - Remote Code Execution (RCE)
CVE-2021-4096420 Jun 2025
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RISK
open
VulnCheck XDB
infoleak
CVE-2014-0160HIGHunder attack20 Jun 2025
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
This is a proof-of-concept exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote code execution via a crafted UDP packet.
CVE-2015-157819 Jun 2025
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-398019 Jun 2025
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware19 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
Metasploit600
Pterodactyl Panel CVE-2025-49132 Remote Code Execution
CVE-2025-49132CRITICAL19 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
Exploit for CVE-2011-2523.
CVE-2011-252319 Jun 2025
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2
CVE-2007-244719 Jun 2025
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
CVE-2019–11043: PHP-FPM Nginx Remote Code Execution Vulnerability
CVE-2019-11043HIGHunder attackransomware19 Jun 2025
Underflow in PHP-FPM can lead to RCE
100RISK
open
GitHub PoC2
CVE-2025-3248 — Langflow RCE Exploit
CVE-2025-3248CRITICALunder attackransomware19 Jun 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC1
Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)
CVE-2024-3094CRITICAL19 Jun 2025
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware19 Jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC
Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)
CVE-2019-15107CRITICALunder attackransomware19 Jun 2025
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH19 Jun 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
initial-access
CVE-2022-41352CRITICALunder attackransomware19 Jun 2025
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RISK
open
previouspage 317 / 2,703next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.