Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
13,235 exploits
GitHub PoC1
A new way to exploit CVE-2025-58360 bypass WAF
CVE-2025-58360HIGHunder attack31 Dec 2025
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open
GitHub PoC
Rishi-kaul/CVE-2025-14847-MongoBleed
CVE-2025-14847HIGHunder attack31 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC2
nkuty/CVE-2025-54322-exploit
CVE-2025-54322CRITICAL31 Dec 2025
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
53RISK
open
GitHub PoC
Goultarde/CVE-2025-55182-React2Shell-Lab
CVE-2025-55182CRITICALunder attackransomware31 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade vers Root (SUID). Ce dépôt contient le rapport technique détaillé, les preuves d'exploitation (PoC) et les mesures de remédiation pour sécuriser l'infrastructure.
CVE-2014-370431 Dec 2025
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RISK
open
GitHub PoC
🎯 Automated vulnerability scanner for React2Shell RCE - Google dorking + safe detection for CVE-2025-55182/CVE-2025-66478 (CVSS 10.0)
CVE-2025-55182CRITICALunder attackransomware30 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It demonstrates how the exploit works, including the payload and impact.
CVE-2025-55182CRITICALunder attackransomware30 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules
CVE-2024-4577CRITICALunder attackransomware30 Dec 2025
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
YanC1e/CVE-2025-8191
CVE-2025-8191MEDIUM30 Dec 2025
macrozheng mall Swagger UI index.html cross site scripting
33RISK
open
GitHub PoC
Remake of CVE-2025-14847 MongoDB vulnerability demonstration
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Udyz/CVE-2025-52691
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC1
This repository contains a safe Proof of Concept (PoC) to detect vulnerable SmarterMail versions affected by CVE‑2025‑52691. The script performs version detection only and does not exploit the vulnerability.
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC3
An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation, persistence, exfiltration, and interactive mode. For educational and authorized testing only. Credits to the original PoC by yt2w/CVE-2025-52691.
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC
Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471
CVE-2022-40471CRITICAL30 Dec 2025
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RISK
open
GitHub PoC2
Academic proof-of-concept demonstrating CVE-2025-68645 for authorized security research.
CVE-2025-68645HIGHunder attack30 Dec 2025
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
GitHub PoC1
CVE-2025-14847 MongoBleed - MongoDB Memory Leak Vulnerability PoC
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
cve-2025-54236 poc
CVE-2025-54236CRITICALunder attack30 Dec 2025
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
GitHub PoC1
This repo contains my python script version of CVE-2025-14847 (MongoBleed)
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE
CVE-2020-0796CRITICALunder attackransomware30 Dec 2025
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.
CVE-2025-14847HIGHunder attack30 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC19
Detection for CVE-2025-52691
CVE-2025-52691CRITICALunder attackransomware30 Dec 2025
Upload Arbitrary Files
100RISK
open
GitHub PoC
Rishi-kaul/n8n-CVE-2025-68613
CVE-2025-68613CRITICALunder attack29 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC4
Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC13
Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
MongoBleed: CVE-2025-14847 Memory Leak Discovery Tool
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
cv-sai-kamesh/n8n-CVE-2025-68613
CVE-2025-68613CRITICALunder attack29 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC1
CVE-2025-14847 – MongoDB Unauthenticated Memory‑Leak Exploit
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC1
aexdyhaxor/CVE-2025-32463
CVE-2025-32463CRITICALunder attack29 Dec 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Context-Aware Memory Leak Scanner & Exploit for CVE-2025-14847.
CVE-2025-14847HIGHunder attack29 Dec 2025
Zlib compressed protocol header length confusion may allow memory read
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.