Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
71,886 exploits
GitHub PoC1
Unauthenticated remote code execution vulnerability in Wing FTP Server <= 7.4.3.
CVE-2025-47812CRITICALunder attack19 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC1
这是基于cve-2016-4437简单的漏洞复现代码
CVE-2016-4437CRITICALunder attack19 Feb 2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
GitHub PoC
CVE-2014-6271 Exploit | by infrar3d
CVE-2014-6271CRITICALunder attack19 Feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC4
CVE-2025-71243 - SPIP Saisies Plugin RCE (Unauthenticated PHP Code Injection)
CVE-2025-71243CRITICAL19 Feb 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISK
open
VulnCheck XDB
local
CVE-2022-24521HIGHunder attackransomware19 Feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
A deep-dive security analysis into the 2020 Virgin Mobile KSA data breach. This study dissects the exploitation of CVE-2020-0688, evaluates the impact of delayed patch management, and proposes a robust multi-layered defense architecture to prevent sophisticated exfiltration tactics.
CVE-2020-0688HIGHunder attackransomware18 Feb 2026
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
GitHub PoC
ross-ns/WSUS-CVE-2025-59287
CVE-2025-59287CRITICALunder attack18 Feb 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
Metasploit500
GrandStream GXP1600 Unauthenticated Remote Code Execution
CVE-2026-2329CRITICAL18 Feb 2026
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
75RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-25600CRITICAL18 Feb 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
info-leak
CVE-2023-31059HIGH18 Feb 2026
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstra
56RISK
open
GitHub PoC
Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow
CVE-2025-4517CRITICAL18 Feb 2026
Arbitrary writes via tarfile realpath overflow
48RISK
open
GitHub PoC1
orgito1015/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALunder attackransomware18 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
Metasploit600
MajorDoMo Remote Command Injection via cycle_execs Race Condition
CVE-2026-27175CRITICAL18 Feb 2026
MajorDoMo Command Injection in rc/index.php via Race Condition
43RISK
open
Metasploit600
MajorDoMo Console Eval Unauthenticated RCE
CVE-2026-27174CRITICAL18 Feb 2026
MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval
63RISK
open
Metasploit600
MajorDoMo Supply Chain RCE via Update Poisoning
CVE-2026-27180CRITICAL18 Feb 2026
MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning
43RISK
open
GitHub PoC
Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication, allowing arbitrary command execution as the web server user.
CVE-2024-25600CRITICAL18 Feb 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
havbay/CVE-2025-47812-PoC
CVE-2025-47812CRITICALunder attack18 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC1
Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server user.
CVE-2019-919418 Feb 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALunder attackransomware18 Feb 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open
VulnCheck XDB
client-side
CVE-2025-47812CRITICALunder attack18 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack18 Feb 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-919418 Feb 2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALunder attack17 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALunder attack17 Feb 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-55182CRITICALunder attackransomware17 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
CVE-2025-47812 POC
CVE-2025-47812CRITICALunder attack17 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
New CVE-2019-7609 which works with python 13
CVE-2019-7609CRITICALunder attack17 Feb 2026
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RISK
open
GitHub PoC
andres101c/Shellshock-CVE-2014-6271
CVE-2014-6271CRITICALunder attack17 Feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack17 Feb 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
CVE-2023-20198CRITICALunder attack17 Feb 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
previouspage 114 / 2,397next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.