Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
71,886 exploits
GitHub PoC
nik123-py/CVE-2025-49132_HTB_SEASON10
CVE-2025-49132CRITICAL14 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
GitHub PoC5
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.
CVE-2025-70830CRITICAL14 Feb 2026
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut
48RISK
open
VulnCheck XDB
local
CVE-2023-42824HIGHunder attack14 Feb 2026
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may
71RISK
open
VulnCheck XDB
initial-access
CVE-2024-37383MEDIUMunder attack14 Feb 2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
85RISK
open
GitHub PoC
Домашняя работа по Pyton № 10 CVE-2020-11022 Краткое описание CVE-2020-11022 — уязвимость типа Reflected XSS (межсайтовый скриптинг), связанная с некорректной обработкой пользовательского ввода, который отражается в HTML-ответе без экранирования. Атакующий может внедрить JavaScript-код, который выполнится в браузере пользователя.
CVE-2020-11022MEDIUM14 Feb 2026
jQuery has a potential XSS vulnerability
55RISK
open
GitHub PoC4
watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553
CVE-2025-40552CRITICAL13 Feb 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware13 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-34102CRITICALunder attack13 Feb 2026
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC1
CVE-2024-34102 exploit for python3
CVE-2024-34102CRITICALunder attack13 Feb 2026
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-1357CRITICAL13 Feb 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH13 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH13 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
GitHub PoC1
针对 Next.js 原型污染漏洞 (CVE-2025-55182) 的高效批量检测工具。
CVE-2025-55182CRITICALunder attackransomware13 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
BIG02-bot/React2Shell-CVE-2025-55182-An-lise-T-cnica
CVE-2025-55182CRITICALunder attackransomware13 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Exploit CVE-2025-49132 Pterodactyl Panel RCE
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
GitHub PoC2
React2Shell (CVE-2025-55182) POC
CVE-2025-55182CRITICALunder attackransomware12 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Real-world information security risk assessment based on the Oracle E-Business Suite zero-day (CVE-2025-61882). Analyses attacker methods, enterprise risks, and mitigation strategies using ISO 27001, NIST CSF, Cyber Essentials and COBIT.
CVE-2025-61882CRITICALunder attackransomware12 Feb 2026
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
GitHub PoC
scroollocker/CVE-2025-49132
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
GitHub PoC3
CVE-2025-49132_PHP_PEAR_METHOD
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH12 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware12 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Sn0wBaall/CVE-2023-4220-PoC
CVE-2023-4220HIGH12 Feb 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH12 Feb 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC
Wise-Security/CVE-2025-69599
CVE-2025-69599CRITICAL11 Feb 2026
RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e
48RISK
open
GitHub PoC
This is a modified version of the time-based SQL injection exploit for CMS Made Simple <= 2.2.9. The exploit was originally created by Daniele Scanu and has been updated for better compatibility and modern Python practices.
CVE-2019-905311 Feb 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL11 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL11 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
previouspage 116 / 2,397next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.