Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
71,886 exploits
VulnCheck XDB
remote-with-credentials
CVE-2024-21413CRITICALunder attack25 Jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Baza-NATO/CVE-2021-33044
CVE-2021-33044CRITICALunder attack25 Jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC2
CVE-2015-2291 Local Privilege Escalation PoC
CVE-2015-2291HIGHunder attackransomware25 Jan 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack25 Jan 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-33044CRITICALunder attack25 Jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC
CVE-2025-60021
CVE-2025-60021CRITICAL25 Jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISK
open
GitHub PoC
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.
CVE-2024-3094CRITICAL25 Jan 2026
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
CVE-2025-64155
CVE-2025-64155CRITICAL25 Jan 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RISK
open
GitHub PoC4
POC (RCE) -> CVE-2019-9978
CVE-2019-9978MEDIUMunder attack25 Jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC
dionissh/CVE-2024-21413
CVE-2024-21413CRITICALunder attack25 Jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2015-2291HIGHunder attackransomware25 Jan 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL25 Jan 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-20045HIGHunder attack25 Jan 2026
Cisco Unified Communications Products Remote Code Execution Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL25 Jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISK
open
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMunder attack25 Jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack25 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack25 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack25 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack24 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-24061CRITICALunder attack24 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack24 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack24 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-38408CRITICAL24 Jan 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC1
A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.
CVE-2021-21311HIGHunder attack24 Jan 2026
SSRF in adminer
100RISK
open
GitHub PoC
xitexploiter96-dot/CVE-2023-38408
CVE-2023-38408CRITICAL24 Jan 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC
For HTB practice
CVE-2022-44268MEDIUM24 Jan 2026
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
GitHub PoC
ranasen-rat/cve-2021-42013
CVE-2021-42013CRITICALunder attackransomware24 Jan 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
client-side
CVE-2021-42013CRITICALunder attackransomware24 Jan 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-23760CRITICALunder attackransomware23 Jan 2026
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-2294CRITICAL23 Jan 2026
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
previouspage 124 / 2,397next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.