Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
8,156 exploits
VulnCheck XDB
infoleak
CVE-2025-282504 Apr 2025
35RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL04 Apr 2025
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-38163CRITICALunder attack04 Apr 2025
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RISK
open
VulnCheck XDB
infoleak
CVE-2025-24799HIGH03 Apr 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISK
open
VulnCheck XDB
infoleak
CVE-2025-24799HIGH03 Apr 2025
GLPI allows unauthenticated SQL injection through the inventory endpoint
78RISK
open
VulnCheck XDB
initial-access
CVE-2025-282503 Apr 2025
35RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL03 Apr 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM03 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
client-side
CVE-2021-44026CRITICALunder attack02 Apr 2025
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
90RISK
open
VulnCheck XDB
initial-access
CVE-2020-1394202 Apr 2025
Remote Code Execution in Apache Unomi
50RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-919302 Apr 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM02 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM02 Apr 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM02 Apr 2025
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
infoleak
CVE-2025-31125MEDIUMunder attack01 Apr 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
90RISK
open
VulnCheck XDB
infoleak
CVE-2022-22536CRITICALunder attack01 Apr 2025
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-50623CRITICALunder attackransomware01 Apr 2025
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH01 Apr 2025
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
infoleak
CVE-2025-2294CRITICAL31 Mar 2025
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
VulnCheck XDB
infoleak
CVE-2025-30208MEDIUM31 Mar 2025
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack31 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH31 Mar 2025
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL31 Mar 2025
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
infoleak
CVE-2024-36991HIGH30 Mar 2025
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL30 Mar 2025
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2012-486930 Mar 2025
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-4587830 Mar 2025
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not
50RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack30 Mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMunder attack30 Mar 2025
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALunder attack30 Mar 2025
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.