Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
71,863 exploits
VulnCheck XDB
info-leak
CVE-2021-43798HIGHunder attack22 Mar 2026
Grafana path traversal
100RISK
open
GitHub PoC
This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables attackers to execute a remote code via injection of the malicious payloads into the log messages.
CVE-2021-44228CRITICALunder attackransomware22 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
This repository presents a comprehensive walkthrough of the Solar Exploiting Log4j room on TryHackMe, with a focus on understanding and exploiting the critical Log4Shell vulnerability (CVE-2021-44228).The process of triggering the exploit and gaining a reverse shell is explained in a practical and easy-to-follow manner.
CVE-2021-44228CRITICALunder attackransomware22 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell vulnerability (CVE-2021-44228). The project demonstrates how attackers can leverage insecure logging mechanisms in Java applications to achieve remote code execution.
CVE-2021-44228CRITICALunder attackransomware22 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for educational purposes
CVE-2014-0160HIGHunder attack22 Mar 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL22 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack22 Mar 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
By PrivacyHunter
CVE-2021-43798HIGHunder attack22 Mar 2026
Grafana path traversal
100RISK
open
GitHub PoC
폰트 인덱스 처리에서 발생하는 signed overflow 취약점
CVE-2023-21716CRITICAL22 Mar 2026
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Lỗ hổng CVE-2025-64446 & CVE-2025-58034
CVE-2025-64446CRITICALunder attack22 Mar 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALunder attackransomware22 Mar 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL22 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2024-36991HIGH21 Mar 2026
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack21 Mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack21 Mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL21 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack21 Mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to achieve root access.
CVE-2011-252321 Mar 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
SALMA-ESSAOUD/CVE-CVSS--CVE-2024-38063-IPv6-TCP-IP-Remote-Code-Execution-Analysis
CVE-2024-38063CRITICAL21 Mar 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Lab & PoC
CVE-2025-53770CRITICALunder attackransomware21 Mar 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
danilo1992-sys/CVE-2021-29447
CVE-2021-29447HIGH20 Mar 2026
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-1492CRITICAL20 Mar 2026
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
68RISK
open
GitHub PoC
Langflow at pre-CVE-2025-3248 fix commit for variant analysis benchmarking
CVE-2025-3248CRITICALunder attackransomware20 Mar 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro
CVE-2025-6934CRITICAL20 Mar 2026
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
GitHub PoC
Classic stack-based buffer overflow in War FTP Daemon 1.65 demonstrating old-school remote code execution through malformed FTP commands.
CVE-2007-156719 Mar 2026
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RISK
open
GitHub PoC
havertz2110/CVE-2024-48510-PoC
CVE-2024-48510CRITICAL19 Mar 2026
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code vi
48RISK
open
GitHub PoC
Exploit based in /jaiguptanick/CVE-2019-0232
CVE-2019-023219 Mar 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC
tayW84/CVE-2019-10945----Python3
CVE-2019-1094519 Mar 2026
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RISK
open
VulnCheck XDB
initial-access
CVE-2025-54236CRITICALunder attack19 Mar 2026
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-023219 Mar 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
previouspage 101 / 2,396next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.