Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
13,264 exploits
GitHub PoC98
CVE-2025-68613: n8n RCE vulnerability exploit and documentation
CVE-2025-68613CRITICALunder attack22 Dec 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC
zaydbf/CVE-2025-9074-Poc
CVE-2025-9074CRITICAL22 Dec 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
GitHub PoC
Vuln lab for CVE-2024-3408 - D-Tale Authentication Bypass & RCE
CVE-2024-3408CRITICAL22 Dec 2025
Authentication Bypass and RCE in man-group/dtale
85RISK
open
GitHub PoC106
This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin mentions that this vulnerability has been used in limited, targeted exploitation in the wild.
CVE-2025-38352HIGHunder attack21 Dec 2025
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
GitHub PoC4
Hello friend. This is the Fsociety Exploit Framework for CVE-2025-24071. Generates malicious .library-ms files to steal NTLMv2 hashes. Includes a 'Living Terminal' Cinematic Mode, Deep Trace logging, and stealth evasion techniques. Join the revolution. #Hacking #Exploit #CVE-2025-24071
CVE-2025-24071MEDIUM21 Dec 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
CVE-2023-32315(java7)
CVE-2023-32315HIGHunder attack21 Dec 2025
Openfire administration console authentication bypass
100RISK
open
GitHub PoC1
NextJS exploiter for CVE-2025-55182 and more.
CVE-2025-55182CRITICALunder attackransomware21 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions
CVE-2025-55182CRITICALunder attackransomware21 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)
CVE-2025-64446CRITICALunder attack21 Dec 2025
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
nicolasdamians/ms09-050-CVE-2009-3103-exploit
CVE-2009-310321 Dec 2025
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open
GitHub PoC1
PoC exploit for CVE-2018-11736 affecting Pluck CMS versions prior to 4.7.7-dev2 with a File Upload Vulnerability
CVE-2018-1173621 Dec 2025
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute a
23RISK
open
GitHub PoC1
CVE-2019-11231 PoC
CVE-2019-1123120 Dec 2025
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RISK
open
GitHub PoC13
FreeBSD rtsold DNSSL Command Injection (RCE)
CVE-2025-14558HIGH20 Dec 2025
Remote code execution via ND6 Router Advertisements
56RISK
open
GitHub PoC
tamagorengs/react2shell-poc-CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware20 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can neutralize a critical Next.js/React Server Actions RCE (CVE-2025-55182 “React2Shell”), with side-by-side safe vs unsafe deployments and exploit logs
CVE-2025-55182CRITICALunder attackransomware20 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC6
CVE-2025-55182 React2Shell PoC - Critical RCE in React Server Components / Next.js. CVSS 10.0. Error-based exfil, reverse shell, interactive mode.
CVE-2025-55182CRITICALunder attackransomware20 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC21
RSC Detect CVE 2025 55182
CVE-2025-55182CRITICALunder attackransomware20 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF practice.
CVE-2025-55182CRITICALunder attackransomware20 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
open-flaw/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain, featuring optional proxy support, automated session elevation, and dynamic command injection via the print scripting engine. Designed for security auditing and authorized penetration testing.
CVE-2023-27350CRITICALunder attackransomware19 Dec 2025
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC1
lamaper/CVE-2025-55182-Toolbox
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC3
React2Shell vulnerability (CVE-2025-55182 / CVE-2025-66478) Full Script
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
A Python-based security scanner for detecting and exploiting **React Server Components (RSC)** vulnerabilities in Next.js applications. This tool performs passive detection, active fingerprinting, and RCE exploitation testing.
CVE-2025-55182CRITICALunder attackransomware19 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC16
Detection for CVE-2025-68461
CVE-2025-68461HIGHunder attack19 Dec 2025
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
76RISK
open
GitHub PoC6
PoC for CVE-2025-37164
CVE-2025-37164CRITICALunder attack19 Dec 2025
A remote code execution issue exists in HPE OneView.
100RISK
open
GitHub PoC1
CVE-2025-13486 - Remote Code Execution & Privilege Escalation exploit
CVE-2025-13486CRITICAL19 Dec 2025
Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form
85RISK
open
GitHub PoC1
CVE-2025-40602 is a local privilege escalation vulnerability in the appliance management console (AMC) of SonicWall Secure Mobile Access (SMA) 1000 series appliances.
CVE-2025-40602MEDIUMunder attack18 Dec 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RISK
open
GitHub PoC
Proof of Concept for Authenticated RCE in Crafty Controller
CVE-2025-14700CRITICAL18 Dec 2025
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
48RISK
open
GitHub PoC3
Detection for CVE-2025-40602
CVE-2025-40602MEDIUMunder attack18 Dec 2025
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance manageme
63RISK
open
GitHub PoC
cyberok-org/CVE-2025-67887
CVE-2025-67887CRITICAL18 Dec 2025
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.