Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
13,264 exploits
GitHub PoC
eytannatye/R2S_CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
PoC, Hunting React2Shell about CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC13
React2Shell is a Python-based proof-of-concept tool designed to exploit CVE-2025-55182 and CVE-2025-66478, both impacting Next.js applications using React Server Components (RSC).
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
amir-malek/react-cve-2025-55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
RCE exploitation tool targeting CVE-2025-55182, a critical vulnerability in React Server Components (RSC) affecting React 19.0.0 - 19.2.0 and Next.js applications.
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2025-55182-advanced-scanner
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
malware I found on my server
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
* React2Shell-CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
A critical vulnerability in React Server Components affecting React 19 (CVE-2025-55182) and frameworks that use it like Next.js (CVE-2025-66478).
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Proof of Concept for CVE-2025-55182 ("React2Shell"). A fully dockerized environment demonstrating Remote Code Execution (RCE) via insecure deserialization in React Server Components. Includes vulnerable targets for both Vanilla React (Express) and Next.js, along with a custom Python exploit script.
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Demo of CVE-2025-55182 — Next.js RCE (for educational purposes)
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC4
CVE-2025-55182-Exploiter Google Chrome Extension. nextjs vulnerability #nextjscve
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
ysfcndgr/React2Shell-CVE-2025-55182-Advanced-Scanner
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Thực hiện để test CVE 2025 55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CVE-2025-55182 检测方式和攻击利用
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
PoC-react2shell-CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Detect CVE-2025-55182 & CVE-2025-66478 in Next.js/RSC applications (Rust)
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Detection of the React Server Actions Exploit vector – CVE-2025-55182 / CVE-2025-66478
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE‑2025‑55182 Detection
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
React2Shell (CVE-2025-55182) proof-of-concept (PoC) exploit demonstrating a CRITICAL remote code execution (RCE) vulnerability in modern web frameworks using React Server Components (RSC).
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
ilixm/PoC-RCE-CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
iamblacksolo2-BugBounty/POC-CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
a simple react2shell poc with basic waf bypass
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
POC-CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
proof
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Python3 script that can be used to demonstrate **CVE-2025-55182**. It exploits a server-side JavaScript injection vulnerability in Next.js/React applications, allowing **remote code execution** via malformed multipart form data.
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC5
POC for React2Shell (CVE-2025-55182)
CVE-2025-55182CRITICALunder attackransomware09 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and macOS (CVSS 9.3)
CVE-2025-9074CRITICAL09 Dec 2025
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
GitHub PoC4
CVE-2025-67511: Tricking a Security AI Agent Into Pwning Itself
CVE-2025-67511CRITICAL09 Dec 2025
Cybersecurity AI (CAI) vulnerable to Command Injection in run_ssh_command_with_credentials Agent tool
48RISK
open
GitHub PoC
Macaroniwdcheese/CVE-2025-55182-Lab
CVE-2025-55182CRITICALunder attackransomware08 Dec 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.