Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
24,459 exploits
Exploit-DB
Stacks Mobile App Builder 5.2.3 - Authentication Bypass via Account Takeover
CVE-2024-50477CRITICALwebappsmultiple08 Jul 2025
WordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
63RISK
open
Exploit-DB
Microsoft Defender for Endpoint (MDE) - Elevation of Privilege
CVE-2025-47161HIGHlocalmultiple08 Jul 2025
Microsoft Defender for Endpoint Elevation of Privilege Vulnerability
41RISK
open
Exploit-DB
Sudo 1.9.17 Host Option - Elevation of Privilege
CVE-2025-32462LOWlocallinux08 Jul 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
Exploit-DB
ScriptCase 9.12.006 (23) - Remote Command Execution (RCE)
CVE-2025-47228MEDIUMremotemultiple08 Jul 2025
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connecti
38RISK
open
Exploit-DB
Sudo chroot 1.9.17 - Local Privilege Escalation
CVE-2025-32463CRITICALunder attacklocallinux08 Jul 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
Exploit-DB
Microsoft Outlook - Remote Code Execution (RCE)
CVE-2025-47171MEDIUMremotewindows08 Jul 2025
Microsoft Outlook Remote Code Execution Vulnerability
33RISK
open
Exploit-DB
Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE)
CVE-2025-47812CRITICALunder attackremotemultiple02 Jul 2025
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
Exploit-DB
Moodle 4.4.0 - Authenticated Remote Code Execution
CVE-2024-43425HIGHwebappsmultiple02 Jul 2025
Moodle: remote code execution via calculated question types
78RISK
open
Exploit-DB
gogs 0.13.0 - Remote Code Execution (RCE)
CVE-2024-39930CRITICALremotemultiple02 Jul 2025
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code
48RISK
open
Exploit-DB
Microsoft SharePoint 2019 - NTLM Authentication
CVE-2025-47166HIGHremotewindows02 Jul 2025
Microsoft SharePoint Server Remote Code Execution Vulnerability
46RISK
open
Exploit-DB
McAfee Agent 5.7.6 - Insecure Storage of Sensitive Information
CVE-2022-1257MEDIUMremotemultiple26 Jun 2025
Improper Verification of Cryptographic Signature by McAfee Agent
33RISK
open
Exploit-DB
Pterodactyl Panel 1.11.11 - Remote Code Execution (RCE)
CVE-2025-49132CRITICALwebappsmultiple26 Jun 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
Exploit-DB
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
CVE-2024-57708MEDIUMremotelinux26 Jun 2025
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __
33RISK
open
Exploit-DB
PX4 Military UAV Autopilot 1.12.3 - Denial of Service (DoS)
CVE-2025-5640MEDIUMremotemultiple26 Jun 2025
PX4-Autopilot TRAJECTORY_REPRESENTATION_WAYPOINTS Message mavlink_receiver.cpp stack-based overflow
33RISK
open
Exploit-DB
Microsoft Excel 2024 Use after free - Remote Code Execution (RCE)
CVE-2025-47165HIGHremotewindows26 Jun 2025
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
Social Warfare WordPress Plugin 3.5.2 - Remote Code Execution (RCE)
CVE-2019-9978MEDIUMunder attackwebappsmultiple26 Jun 2025
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
Exploit-DB
Sitecore 10.4 - Remote Code Execution (RCE)
CVE-2025-27218MEDIUMwebappsmultiple26 Jun 2025
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through
60RISK
open
Exploit-DB
freeSSHd 1.0.9 - Denial of Service (DoS)
CVE-2024-0723MEDIUMremotewindows26 Jun 2025
freeSSHd denial of service
33RISK
open
Exploit-DBVexDay Proof
Ingress-NGINX 4.11.0 - Remote Code Execution (RCE)
CVE-2025-1974CRITICALremotemultiple20 Jun 2025
ingress-nginx admission controller RCE escalation
85RISK
open
Exploit-DB
FortiOS SSL-VPN 7.4.4 - Insufficient Session Expiration & Cookie Reuse
CVE-2024-50562MEDIUMremotemultiple20 Jun 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, ve
33RISK
open
Exploit-DB
Microsoft Excel LTSC 2024 - Remote Code Execution (RCE)
CVE-2025-47957HIGHlocalwindows20 Jun 2025
Microsoft Word Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
Microsoft Excel Use After Free - Local Code Execution
CVE-2025-27751HIGHlocalwindows15 Jun 2025
Microsoft Excel Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
PCMan FTP Server 2.0.7 - Buffer Overflow
CVE-2025-4255MEDIUMremotewindows15 Jun 2025
PCMan FTP Server RMD Command buffer overflow
33RISK
open
Exploit-DB
Anchor CMS 0.12.7 - Stored Cross Site Scripting (XSS)
CVE-2025-46041MEDIUMwebappsphp15 Jun 2025
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript
33RISK
open
Exploit-DB
Windows 11 SMB Client - Privilege Escalation & Remote Code Execution (RCE)
CVE-2025-33073HIGHunder attackremotewindows15 Jun 2025
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
Exploit-DB
PHP CGI Module 8.3.4 - Remote Code Execution (RCE)
CVE-2024-4577CRITICALunder attackransomwarewebappsphp15 Jun 2025
Argument Injection in PHP-CGI
100RISK
open
Exploit-DB
Parrot and DJI variants Drone OSes - Kernel Panic Exploit
CVE-2025-37928localmultiple15 Jun 2025
dm-bufio: don't schedule in atomic context
23RISK
open
Exploit-DB
Freefloat FTP Server 1.0 - Remote Buffer Overflow
CVE-2025-5548MEDIUMremotemultiple13 Jun 2025
FreeFloat FTP Server NOOP Command buffer overflow
38RISK
open
Exploit-DB
Windows File Explorer Windows 10 Pro x64 - TAR Extraction
CVE-2025-24071MEDIUMremotewindows13 Jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
Exploit-DB
Roundcube 1.6.10 - Remote Code Execution (RCE)
CVE-2025-49113CRITICALunder attackwebappsmultiple13 Jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.