Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware24 Apr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-34028CRITICALunder attack24 Apr 2025
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware24 Apr 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-7120MEDIUM24 Apr 2025
Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-282524 Apr 2025
35RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-30406CRITICALunder attack24 Apr 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack24 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM24 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware24 Apr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL24 Apr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack23 Apr 2025
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-24963MEDIUM23 Apr 2025
Browser mode serves arbitrary files in vitest
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-29306CRITICAL22 Apr 2025
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.htm
75RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM22 Apr 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
client-side
CVE-2025-24054MEDIUMunder attack22 Apr 2025
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack22 Apr 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack22 Apr 2025
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
VulnCheck XDB
initial-access
CVE-2024-28987CRITICALunder attack21 Apr 2025
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware21 Apr 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM21 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
client-side
CVE-2025-24071MEDIUM21 Apr 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
initial-access
CVE-2025-24016CRITICALunder attack21 Apr 2025
Remote code execution in Wazuh server
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-25157CRITICAL21 Apr 2025
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-31161CRITICALunder attackransomware21 Apr 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
client-side
CVE-2020-35730MEDIUMunder attack20 Apr 2025
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attack
75RISK
open
VulnCheck XDB
client-side
CVE-2021-44026CRITICALunder attack20 Apr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISK
open
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALunder attack20 Apr 2025
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack20 Apr 2025
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.