Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
8,150 exploits
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM06 Jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-14871CRITICALunder attack06 Jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware06 Jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware06 Jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack05 Jun 2025
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
infoleak
CVE-2022-46604HIGH05 Jun 2025
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-32756CRITICALunder attack05 Jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack05 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
client-side
CVE-2025-4123HIGH04 Jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
VulnCheck XDB
infoleak
CVE-2025-2539HIGH04 Jun 2025
File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
56RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack04 Jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-20085HIGHunder attack04 Jun 2025
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL03 Jun 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-3102HIGH03 Jun 2025
SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
78RISK
open
VulnCheck XDB
client-side
CVE-2025-4123HIGH03 Jun 2025
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
78RISK
open
VulnCheck XDB
infoleak
CVE-2023-27163MEDIUM03 Jun 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
infoleak
CVE-2018-999502 Jun 2025
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
VulnCheck XDB
initial-access
CVE-2008-4250CRITICALunder attack02 Jun 2025
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-25690CRITICAL01 Jun 2025
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL31 May 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISK
open
VulnCheck XDB
client-side
CVE-2025-30397HIGHunder attack31 May 2025
Scripting Engine Memory Corruption Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware31 May 2025
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-5287HIGH31 May 2025
Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection
56RISK
open
VulnCheck XDB
initial-access
CVE-2024-7399HIGHunder attack30 May 2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-26828HIGHunder attack30 May 2025
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
83RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-2291129 May 2025
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL29 May 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-48827CRITICAL29 May 2025
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM29 May 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware28 May 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.