Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
8,722 exploits
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack27 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack27 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack27 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack27 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-14847HIGHunder attack26 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware26 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack26 Dec 2025
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack26 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware26 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware26 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-14847HIGHunder attack26 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack25 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack25 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack25 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack25 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack25 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
client-side
CVE-2016-15041HIGH25 Dec 2025
MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting
56RISK
open
VulnCheck XDB
client-side
CVE-2016-15041HIGH25 Dec 2025
MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting
56RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack25 Dec 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware25 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack24 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware24 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
client-side
CVE-2017-20192HIGH24 Dec 2025
Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting
56RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack24 Dec 2025
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack24 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
local
CVE-2025-62215HIGHunder attack23 Dec 2025
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-54068CRITICALunder attack23 Dec 2025
Livewire vulnerable to remote command execution during property update hydration
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack23 Dec 2025
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-68613CRITICALunder attack23 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.