Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
81,064 exploits
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALunder attack10 Jun 2025
Remote code execution in Wazuh server
100RISK
open
Metasploit600
Pandora ITSM authenticated command injection leading to RCE via the backup function
CVE-2025-4653HIGH10 Jun 2025
Remote Code Execution leads to Command Injection
36RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack10 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
Metasploit600
n8n Workflow Expression Remote Code Execution
CVE-2025-68613CRITICALunder attack10 Jun 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC6
A PoC exploit for CVE-2017-9841 - PHPUnit Remote Code Execution(RCE)
CVE-2017-9841CRITICALunder attack10 Jun 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC
CVE-2025-24071
CVE-2025-24071MEDIUM10 Jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC6
Proof-of-concept to CVE-2025-49113
CVE-2025-49113CRITICALunder attack10 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC2
Detection for CVE-2025-24016 - Deserialization of Untrusted Data Vulnerability in the Wazuh software
CVE-2025-24016CRITICALunder attack10 Jun 2025
Remote code execution in Wazuh server
100RISK
open
GitHub PoC3
Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability
CVE-2025-24071MEDIUM09 Jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
Exploit-DB
TightVNC 2.8.83 - Control Pipe Manipulation
CVE-2024-42049CRITICALlocalmultiple09 Jun 2025
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
48RISK
open
Exploit-DB
Microsoft Windows 11 Version 24H2 Cross Device Service - Elevation of Privilege
CVE-2025-24076HIGHlocalwindows09 Jun 2025
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISK
open
Exploit-DB
ProSSHD 1.2 20090726 - Denial of Service (DoS)
CVE-2024-0725MEDIUMremotewindows09 Jun 2025
ProSSHD denial of service
33RISK
open
GitHub PoC
CVE-2021-3156-Exploit-Demo
CVE-2021-3156HIGHunder attack09 Jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack09 Jun 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-2539HIGH09 Jun 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM09 Jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM09 Jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack09 Jun 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-10914CRITICAL09 Jun 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
VulnCheck XDB
local
CVE-2021-36934HIGHunder attack09 Jun 2025
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
Arshit01/CVE-2023-20198
CVE-2023-20198CRITICALunder attack09 Jun 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC1
CVE-2025-29927 - Critical Security Vulnerability in Next.js
CVE-2025-29972CRITICAL09 Jun 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49619HIGH09 Jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware09 Jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL09 Jun 2025
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
alm6no5/CVE-2025-32756-POC
CVE-2025-32756CRITICALunder attack09 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
83RISK
open
Exploit-DB
Laravel Pulse 1.3.1 - Arbitrary Code Injection
CVE-2024-55661HIGHwebappsphp09 Jun 2025
Laravel Pulse Allows Remote Code Execution via Unprotected Query Method
46RISK
open
GitHub PoC
CVE-2025-32756: NSE Scanning for RCE in vulnerable FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera nodes
CVE-2025-32756CRITICALunder attack09 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
83RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-32756CRITICALunder attack09 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
83RISK
open
GitHub PoC3
This script exploits CVE-2025-49619 in Skyvern to execute a reverse shell command.
CVE-2025-49619HIGH09 Jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RISK
open
previouspage 321 / 2,703next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.