Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
8,722 exploits
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack06 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-37164CRITICALunder attack06 Jan 2026
A remote code execution issue exists in HPE OneView.
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-5932CRITICAL06 Jan 2026
GiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware06 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware06 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware06 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware05 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-2011HIGH05 Jan 2026
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open
VulnCheck XDB
client-side
CVE-2025-43529HIGHunder attack05 Jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-13390CRITICAL05 Jan 2026
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware05 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack05 Jan 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-14998CRITICAL05 Jan 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover
48RISK
open
VulnCheck XDB
initial-access
CVE-2019-1420604 Jan 2026
An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote a
38RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-28205HIGHunder attack04 Jan 2026
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 a
76RISK
open
VulnCheck XDB
client-side
CVE-2025-55182CRITICALunder attackransomware04 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
client-side
CVE-2025-14174HIGHunder attack04 Jan 2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack03 Jan 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-38352HIGHunder attack03 Jan 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware03 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL03 Jan 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2022-4288902 Jan 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL02 Jan 2026
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
local
CVE-2025-14174HIGHunder attack02 Jan 2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISK
open
VulnCheck XDB
info-leak
CVE-2019-9978MEDIUMunder attack01 Jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware01 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack01 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack01 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-0288HIGH01 Jan 2026
CVE-2025-0288
41RISK
open
VulnCheck XDB
info-leak
CVE-2025-68645HIGHunder attack01 Jan 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.