Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,814cataloged exploits
32,125CVEs with public exploitation
1,932lab-tested
8,150 exploits
VulnCheck XDB
infoleak
CVE-2024-51977MEDIUM22 May 2025
Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.
70RISK
open
VulnCheck XDB
initial-access
CVE-2024-9463CRITICALunder attack22 May 2025
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-21762CRITICALunder attackransomware22 May 2025
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-4322CRITICAL21 May 2025
Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
68RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2020-10199HIGHunder attack21 May 2025
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware21 May 2025
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-0012CRITICALunder attackransomware21 May 2025
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack21 May 2025
Unauthenticated Command Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-9474MEDIUMunder attackransomware21 May 2025
PAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL20 May 2025
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
VulnCheck XDB
infoleak
CVE-2021-43798HIGHunder attack19 May 2025
Grafana path traversal
100RISK
open
VulnCheck XDB
client-side
CVE-2021-38003HIGHunder attack19 May 2025
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially explo
83RISK
open
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMunder attack19 May 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-32756CRITICALunder attack18 May 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RISK
open
VulnCheck XDB
infoleak
CVE-2024-41713CRITICALunder attackransomware18 May 2025
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could
100RISK
open
VulnCheck XDB
local
CVE-2024-44258HIGH18 May 2025
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18
41RISK
open
VulnCheck XDB
local
CVE-2025-0288HIGH17 May 2025
CVE-2025-0288
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-47539CRITICAL17 May 2025
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack16 May 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-4428HIGHunder attack16 May 2025
Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3605CRITICAL15 May 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack15 May 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack15 May 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-4428HIGHunder attack15 May 2025
Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-4427MEDIUMunder attack15 May 2025
Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-27636MEDIUM14 May 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
55RISK
open
VulnCheck XDB
local
CVE-2025-29824HIGHunder attackransomware14 May 2025
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALunder attack14 May 2025
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack14 May 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack13 May 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.