Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,064cataloged exploits
37,667CVEs with public exploitation
24,695lab-tested
81,064 exploits
GitHub PoC1
Proof of Concept for CVE-2024-9463
CVE-2024-9463CRITICALunder attack22 May 2025
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-4322CRITICAL22 May 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-51978CRITICAL22 May 2025
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RISK
open
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALunder attackransomware22 May 2025
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
GitHub PoC2
Public disclosure of CVE-2025-31200 – Zero-click RCE in iOS 18.X via AudioConverterService and malicious audio file.
CVE-2025-31200CRITICALunder attack22 May 2025
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4
83RISK
open
VulnCheck XDB
initial-access
CVE-2024-9463CRITICALunder attack22 May 2025
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RISK
open
GitHub PoC58
Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF
CVE-2025-4123HIGH22 May 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
VulnCheck XDB
infoleak
CVE-2024-51977MEDIUM22 May 2025
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RISK
open
GitHub PoC2
Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.
CVE-2024-21762CRITICALunder attackransomware22 May 2025
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
GitHub PoC1
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image Task
CVE-2025-5058CRITICAL21 May 2025
eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_image()
48RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware21 May 2025
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware21 May 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
GitHub PoC5
Exploitation and Post-Exploitation Multitool for Palo Alto PAN-OS Systems affected by vulnerabilities CVE-2024-0012 and CVE-2024-9474
CVE-2024-0012CRITICALunder attackransomware21 May 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack21 May 2025
Unauthenticated Command Injection
100RISK
open
GitHub PoC
RdBBB3/SHELL-POC-CVE-2022-46169
CVE-2022-46169CRITICALunder attack21 May 2025
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware21 May 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack21 May 2025
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-4322CRITICAL21 May 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISK
open
GitHub PoC
CVE-2021-34527 is a critical remote code execution and local privilege escalation vulnerability dubbed "PrintNightmare."
CVE-2021-34527HIGHunder attackransomware21 May 2025
Windows Print Spooler Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
finn79426/CVE-2020-10199
CVE-2020-10199HIGHunder attack21 May 2025
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-1974CRITICAL20 May 2025
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC
PoC for CVE-2025-47646 - WordPress PSW Front-end Login Registration Plugin ≤ 1.12 Unauthenticated Privilege Escalation
CVE-2025-47646CRITICAL20 May 2025
WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
68RISK
open
GitHub PoC
CVE-2024-53677
CVE-2024-53677CRITICAL20 May 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC
It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only certain operating systems and operating system versions were affected by this vulnerability.
CVE-2024-3094CRITICAL20 May 2025
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL20 May 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL20 May 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RISK
open
GitHub PoC2
PoC and vulnerability report for CVE-2025-47827.
CVE-2025-47827MEDIUMunder attack20 May 2025
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptograph
63RISK
open
GitHub PoC1
IndominusRexes/CVE-2025-4322-Exploit
CVE-2025-4322CRITICAL20 May 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISK
open
VulnCheck XDB
client-side
CVE-2021-38003HIGHunder attack19 May 2025
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
83RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack19 May 2025
Grafana path traversal
100RISK
open
previouspage 328 / 2,703next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.