Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
8,829 exploits
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL09 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL09 Jun 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
client-side
CVE-2025-11262HIGH09 Jun 2026
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALunder attack09 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-8054CRITICAL09 Jun 2026
Unauthenticated SQL Injection in dotCMS Publish Audit API
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALunder attack08 Jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-21716CRITICAL08 Jun 2026
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2018-1676308 Jun 2026
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack08 Jun 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack08 Jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-7465HIGH08 Jun 2026
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL08 Jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack08 Jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack07 Jun 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALunder attack07 Jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack07 Jun 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL07 Jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware07 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-5777CRITICALunder attackransomware07 Jun 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware07 Jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALunder attack07 Jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-9082CRITICALunder attack07 Jun 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-46604CRITICALunder attackransomware06 Jun 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack06 Jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL06 Jun 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALunder attack06 Jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALunder attack06 Jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack06 Jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-1492CRITICAL06 Jun 2026
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
68RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack06 Jun 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.