Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
3,489 exploits
Metasploit300
N-able N-Central Authentication Bypass and XXE Scanner
CVE-2025-11700HIGH17 Nov 2025
N-central Multiple XXE Injection Vulnerabilities
68RISK
open
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
Metasploit300
Fortinet FortiWeb create new local admin
CVE-2025-64446CRITICALunder attack14 Nov 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
Metasploit600
Fortinet FortiWeb unauthenticated RCE
CVE-2025-58034MEDIUMunder attack14 Nov 2025
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
90RISK
open
Metasploit600
FreePBX filestore authenticated command injection
CVE-2025-64328HIGHunder attack08 Nov 2025
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
100RISK
open
Metasploit600
Monsta FTP downloadFile Remote Code Execution
CVE-2025-34299CRITICAL07 Nov 2025
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RISK
open
Metasploit600
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
CVE-2025-11749CRITICAL04 Nov 2025
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
85RISK
open
Metasploit600
WordPress King Addons for Elementor Unauthenticated Privilege Escalation to RCE
CVE-2025-8489CRITICAL30 Oct 2025
King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation
43RISK
open
Metasploit600
Taiga tribe_gig authenticated unserialize remote code execution
CVE-2025-62368CRITICAL28 Oct 2025
Taiga Authenticated Remote Code Execution
43RISK
open
Metasploit600
Magento SessionReaper
CVE-2025-54236CRITICALunder attack22 Oct 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
Metasploit500
Windows Server Update Service Deserialization Remote Code Execution
CVE-2025-59287CRITICALunder attack14 Oct 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
Metasploit600
SmarterTools SmarterMail GUID File Upload Vulnerability
CVE-2025-52691CRITICALunder attackransomware09 Oct 2025
Upload Arbitrary Files
100RISK
open
Metasploit600
Oracle E-Business Suite CVE-2025-61882 RCE
CVE-2025-61882CRITICALunder attackransomware04 Oct 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
Metasploit600
Centreon authenticated command injection leading to RCE via broker engine "reload" parameter
CVE-2025-5946HIGH24 Sep 2025
RCE via the poller reload feature available only to user with high privilege
41RISK
open
Metasploit600
Flowise JS Injection RCE
CVE-2025-59528CRITICAL13 Sep 2025
Flowise has Remote Code Execution vulnerability
85RISK
open
Metasploit600
Remote Code Execution Vulnerability in MotionEye Frontend (CVE-2025-60787)
CVE-2025-60787HIGH09 Sep 2025
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
Metasploit600
FreePBX ajax.php unauthenticated SQLi to RCE
CVE-2025-57819CRITICALunder attack28 Aug 2025
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57791MEDIUM19 Aug 2025
Argument Injection Vulnerability in CommServe
33RISK
open
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57790HIGH19 Aug 2025
Path Traversal Vulnerability
41RISK
open
Metasploit600
Commvault Command-Line Argument Injection to Traversal Remote Code Execution
CVE-2025-57788MEDIUM19 Aug 2025
Unauthorized API Access Risk
28RISK
open
Metasploit600
Flowise Custom MCP Remote Code Execution
CVE-2025-8943CRITICAL14 Aug 2025
Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers
65RISK
open
Metasploit600
Grav CMS Admin Direct Install Authenticated Plugin Upload RCE
CVE-2025-50286HIGH07 Aug 2025
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RISK
open
Metasploit400
Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (time param)
CVE-2025-34152CRITICAL07 Aug 2025
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RISK
open
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Template Import
CVE-2026-32985CRITICAL04 Aug 2025
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
63RISK
open
Metasploit600
WordPress StoryChief Plugin Unauthenticated RCE
CVE-2025-7441CRITICAL04 Aug 2025
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
75RISK
open
Metasploit600
Template Injection Vulnerability in Sawtooth Software's Lighthouse Studio (CVE-2025-34300)
CVE-2025-34300CRITICAL16 Jul 2025
Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
75RISK
open
Metasploit600
PivotX Remote Code Execution
CVE-2025-52367MEDIUM10 Jul 2025
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RISK
open
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-53771MEDIUM08 Jul 2025
Microsoft SharePoint Server Spoofing Vulnerability
50RISK
open
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-49704HIGHunder attackransomware08 Jul 2025
Microsoft SharePoint Remote Code Execution Vulnerability
88RISK
open
Metasploit600
Microsoft SharePoint Server ToolPane Unauthenticated Remote Code Execution (aka ToolShell)
CVE-2025-53770CRITICALunder attackransomware08 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.