Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
71,886 exploits
VulnCheck XDB
local
CVE-2022-24481HIGH25 Feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
46RISK
open
GitHub PoC
TeneBrae93/RocketChat-NoSQLi-Chain-CVE-2021-22911
CVE-2021-2291125 Feb 2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
GitHub PoC1
PoC for CVE-2023-43208 RCE exploitation.
CVE-2023-43208CRITICALunder attackransomware25 Feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
mirth-connect-rce-poc
CVE-2023-43208CRITICALunder attackransomware25 Feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC1
0xjuarez/CVE-2025-47812
CVE-2025-47812CRITICALunder attack24 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC2
The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP defenses.
CVE-2025-38352HIGHunder attack24 Feb 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
GitHub PoC3
A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4.1.
CVE-2023-43208CRITICALunder attackransomware24 Feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
GitHub PoC
Unauthenticated remote code execution vulnerability in SPIP before 4.2.1.
CVE-2023-27372CRITICAL24 Feb 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware24 Feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-32433CRITICALunder attack24 Feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-0770CRITICALunder attack24 Feb 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2026-21858CRITICAL24 Feb 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware24 Feb 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-47812CRITICALunder attack24 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
client-side
CVE-2023-27372CRITICAL24 Feb 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC
carlosalbertotuma/CVE-2025-32433
CVE-2025-32433CRITICALunder attack24 Feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC
SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)
CVE-2021-20038CRITICALunder attackransomware23 Feb 2026
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows
100RISK
open
GitHub PoC
CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware23 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)
CVE-2024-53704HIGHunder attackransomware23 Feb 2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware23 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-31161CRITICALunder attackransomware23 Feb 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-2441HIGHunder attack23 Feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISK
open
VulnCheck XDB
initial-access
CVE-2024-53704HIGHunder attackransomware23 Feb 2026
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-47539CRITICAL23 Feb 2026
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
75RISK
open
GitHub PoC
Wrote an exploit in Go for CVE-2025-31161 affecting crushFTP.
CVE-2025-31161CRITICALunder attackransomware23 Feb 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC
CVE-2025-14847
CVE-2025-14847HIGHunder attack23 Feb 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC2
tempiltin/CVE-2025-10353-POC
CVE-2025-10353CRITICAL23 Feb 2026
Missing Authorization vulnerability in Melis Platform
63RISK
open
GitHub PoC
Stored Cross-Site Scripting in "usememos" via SVG
CVE-2025-50738CRITICAL22 Feb 2026
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us
48RISK
open
GitHub PoC1
Educational lab demonstrating CVE-2021-36934 (HiveNightmare) - Windows LPE via shadow copy ACL misconfiguration.
CVE-2021-36934HIGHunder attack22 Feb 2026
Windows Elevation of Privilege Vulnerability
98RISK
open
GitHub PoC
RCE for WingFTP v4.7.3
CVE-2025-47812CRITICALunder attack22 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
previouspage 112 / 2,397next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.