Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,150 exploits
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL13 May 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
VulnCheck XDB
infoleak
CVE-2022-21661HIGH13 May 2025
SQL injection in WordPress
78RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack13 May 2025
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
local
CVE-2025-24085CRITICALunder attack13 May 2025
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, i
83RISK
open
VulnCheck XDB
local
CVE-2021-3156HIGHunder attack12 May 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware12 May 2025
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
client-side
CVE-2025-0411HIGHunder attack11 May 2025
7-Zip Mark-of-the-Web Bypass Vulnerability
83RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack11 May 2025
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-42793CRITICALunder attackransomware11 May 2025
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack11 May 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack10 May 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL10 May 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-31324CRITICALunder attackransomware10 May 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-3605CRITICAL09 May 2025
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL09 May 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
client-side
CVE-2025-2748MEDIUM09 May 2025
Kentico Xperience stored cross-site scripting in multiple-file upload functionality
60RISK
open
VulnCheck XDB
infoleak
CVE-2025-31324CRITICALunder attackransomware08 May 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-2564608 May 2025
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
VulnCheck XDB
infoleak
CVE-2025-29927CRITICAL08 May 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-6648HIGH08 May 2025
Path Traversal in AP Page Builder
41RISK
open
VulnCheck XDB
infoleak
CVE-2025-31125MEDIUMunder attack07 May 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISK
open
VulnCheck XDB
initial-access
CVE-2025-27007CRITICAL07 May 2025
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-31324CRITICALunder attackransomware07 May 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-38475CRITICALunder attack07 May 2025
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-34028CRITICALunder attack06 May 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-31324CRITICALunder attackransomware06 May 2025
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL06 May 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-34028CRITICALunder attack06 May 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-2011HIGH06 May 2025
Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
68RISK
open
VulnCheck XDB
infoleak
CVE-2025-31125MEDIUMunder attack05 May 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.