Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
8,150 exploits
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack02 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack01 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
client-side
CVE-2025-6218HIGHunder attack01 Jul 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2025-20282CRITICAL01 Jul 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
48RISK
open
VulnCheck XDB
infoleak
CVE-2025-49493MEDIUM01 Jul 2025
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack01 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack01 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack01 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack01 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-47812CRITICALunder attack01 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1198430 Jun 2025
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
60RISK
open
VulnCheck XDB
client-side
CVE-2025-6218HIGHunder attack29 Jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM29 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
info-leak
CVE-2016-20016CRITICAL29 Jun 2025
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RISK
open
VulnCheck XDB
client-side
CVE-2025-4664MEDIUM29 Jun 2025
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cro
33RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL29 Jun 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH29 Jun 2025
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
initial-access
CVE-2024-54085CRITICALunder attack29 Jun 2025
Redfish Authentication Bypass
90RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHunder attack28 Jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2023-30258CRITICAL28 Jun 2025
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary com
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-20281CRITICALunder attack27 Jun 2025
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
client-side
CVE-2025-6218HIGHunder attack27 Jun 2025
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability
93RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM27 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
local
CVE-2025-21756HIGH26 Jun 2025
vsock: Keep the binding until socket destruction
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-48703CRITICALunder attack26 Jun 2025
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
100RISK
open
VulnCheck XDB
local
CVE-2019-573625 Jun 2025
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
VulnCheck XDB
infoleak
CVE-2024-10924CRITICAL25 Jun 2025
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-49132CRITICAL25 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-48828CRITICAL25 Jun 2025
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RISK
open
VulnCheck XDB
initial-access
CVE-2024-43917CRITICAL25 Jun 2025
WordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
68RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.