Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
71,886 exploits
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware12 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware12 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
hook repo for cve-2024-32002
CVE-2024-32002CRITICAL12 Mar 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
CVE-2024-32002 Private for Capstone Project CC10
CVE-2024-32002CRITICAL12 Mar 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Scripts en Python para la explotación de CVE-2024-51482 (SQLi en ZoneMinder) — HTB CCTV
CVE-2024-51482CRITICAL11 Mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC1
CVE-2023-6329 – Authentication bypass PoC for Control iD iDSecure ≤ 4.7.43.0
CVE-2023-6329CRITICAL11 Mar 2026
Control iD iDSecure passwordCustom Authentication Bypass
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-6329CRITICAL11 Mar 2026
Control iD iDSecure passwordCustom Authentication Bypass
75RISK
open
GitHub PoC
A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".
CVE-2021-3156HIGHunder attack11 Mar 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware11 Mar 2026
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2019-10068CRITICALunder attack11 Mar 2026
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISK
open
GitHub PoC6
MistyFir/CVE-2024-21338-Exploit
CVE-2024-21338HIGHunder attackransomware11 Mar 2026
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
GitHub PoC
Advanced SMB Honeypot: CVE-2025-33073 Research & Implementation
CVE-2025-33073HIGHunder attack11 Mar 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
GitHub PoC
michalAshurov/writeup-CVE-2024-3094
CVE-2024-3094CRITICAL11 Mar 2026
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Proof of concept exploit for CVE-2019-10068.
CVE-2019-10068CRITICALunder attack11 Mar 2026
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISK
open
GitHub PoC
engranaabubakar/CVE-2022-42889
CVE-2022-4288910 Mar 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC2
CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod çalıştırılmasına (unauthorized rce & lateral movement) olanak tanıyan kritik güvenlik zafiyeti.
CVE-2026-6508CRITICAL10 Mar 2026
RCE in TUBITAK BILGEM's Liderahenk
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-27944CRITICAL10 Mar 2026
Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
68RISK
open
GitHub PoC2
CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC
CVE-2025-66398CRITICAL10 Mar 2026
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
53RISK
open
GitHub PoC
Writeup of the Optimum machine from Hack The Box. This walkthrough covers the exploitation of Rejetto HttpFileServer 2.3 (CVE-2014-6287) to gain initial access, followed by privilege escalation on a Windows host using enumeration techniques and post-exploitation tools.
CVE-2014-6287CRITICALunder attack10 Mar 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC5
Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and Sandbox Escape
CVE-2024-23222HIGHunder attack10 Mar 2026
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.
76RISK
open
GitHub PoC
OpenSSH User Enumeration (CVE-2018-15473) Lab
CVE-2018-15473MEDIUM09 Mar 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC
VX Search Enterprise v10.1.12 Remote Buffer Overflow
CVE-2017-1522009 Mar 2026
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginni
23RISK
open
GitHub PoC
swoon69/CVE-2025-59287-Exercise-Use
CVE-2025-59287CRITICALunder attack09 Mar 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-20127CRITICALunder attack09 Mar 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHunder attack09 Mar 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
client-side
CVE-2026-25253HIGH09 Mar 2026
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack09 Mar 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
CVE-2025-49844
CVE-2025-49844CRITICAL09 Mar 2026
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
GitHub PoC
OpenSSH regreSSHion (CVE-2024-6387) Lab
CVE-2024-6387HIGH09 Mar 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
gregk4sec/cve-2025-31651
CVE-2025-31651CRITICAL09 Mar 2026
Apache Tomcat: Bypass of rules in Rewrite Valve
48RISK
open
previouspage 106 / 2,397next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.