Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,329cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DB
Grav CMS 2.0.0-beta.2 - Remote Code Execution
CVE-2026-42607CRITICALwebappsphp26 May 2026
Grav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
48RISK
open
Exploit-DB
cPanel - CRLF Injection
CVE-2026-41940CRITICALunder attackransomwarewebappsphp26 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Exploit-DB
Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service
CVE-2026-23918HIGHwebappsmultiple26 May 2026
Apache HTTP Server: http2: double free and possible RCE on early reset
53RISK
open
Exploit-DB
Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover
CVE-2026-7567CRITICALwebappsmultiple26 May 2026
Temporary Login <= 1.0.0 - Authentication Bypass to Account Takeover
48RISK
open
Exploit-DB
FUXA 1.2.9 - RCE
CVE-2026-25895CRITICALwebappsmultiple21 May 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RISK
open
Exploit-DB
Cockpit 359 - RCE
CVE-2026-4631CRITICALwebappsmultiple21 May 2026
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
68RISK
open
Exploit-DB
Windows Snipping Tool - NTLMv2 Hash Hijack
CVE-2026-33829MEDIUMlocalwindows15 May 2026
Windows Snipping Tool Spoofing Vulnerability
33RISK
open
Exploit-DB
WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI
CVE-2026-4257CRITICALwebappsmultiple14 May 2026
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
75RISK
open
Exploit-DB
ePati Antikor NGFW 2.0.1301 - Authentication Bypass
CVE-2026-2624CRITICALwebappsmultiple14 May 2026
Authentication Bypass in ePati's Antikor NGFW
48RISK
open
Exploit-DB
PJPROJECT 2.16 - Heap Bufferoverflow
CVE-2026-25994HIGHwebappsmultiple14 May 2026
PJSIP has a heap buffer overflow in ICE with long username
41RISK
open
Exploit-DB
Ninja Forms Uploads - Unauthenticated PHP File Upload
CVE-2026-0740CRITICALwebappsmultiple13 May 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
Exploit-DB
Flowise < 3.0.5 - Missing Authentication for Critical Function
CVE-2025-58434CRITICALwebappstypescript13 May 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISK
open
Exploit-DB
coreruleset 4.21.0 - Firewall Bypass
CVE-2026-21876CRITICALwebappsmultiple13 May 2026
OWASP CRS has multipart bypass using multiple content-type parts
53RISK
open
Exploit-DB
glances 4.5.2 - command injection
CVE-2026-33641HIGHwebappsmultiple13 May 2026
Glances Vulnerable to Command Injection via Dynamic Configuration Values
41RISK
open
Exploit-DB
telnetd 2.7 - Buffer Overflow
CVE-2026-32746CRITICALremotemultiple07 May 2026
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RISK
open
Exploit-DB
NocoBase 2.0.27 - VM Sandbox Escape
CVE-2026-34156CRITICALlocalmultiple07 May 2026
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
75RISK
open
Exploit-DB
Ghost CMS 6.19.0 - SQLi
CVE-2026-26980CRITICALwebappsmultiple07 May 2026
Ghost has a SQL Injection in its Content API
75RISK
open
Exploit-DB
ThingsBoard IoT Platform 4.2.0 - Server-Side Request Forgery (SSRF)
CVE-2025-34282MEDIUMwebappsmultiple07 May 2026
ThingsBoard < v4.2.1 SVG Image SSRF
33RISK
open
Exploit-DB
Bludit CMS 3.18.4 - RCE
CVE-2026-25099HIGHwebappsmultiple07 May 2026
Remote Code Execution via Unrestricted File Upload in Bludit
41RISK
open
Exploit-DB
Linux nf_tables 6.19.3 - Local Privilege Escalation
CVE-2026-23231HIGHlocallinux04 May 2026
netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
41RISK
open
Exploit-DB
Traccar GPS Tracking System 6.11.1 - Cross-Site WebSocket Hijacking (CSWSH)
CVE-2025-68930HIGHwebappsmultiple04 May 2026
Traccar Missing Origin Validation in WebSockets
41RISK
open
Exploit-DB
MindsDB 25.9.1.1 - Path Traversal
CVE-2026-27483HIGHwebappsmultiple04 May 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RISK
open
Exploit-DB
Windows 11 24H2 - Local Privilege Escalation
CVE-2026-21250HIGHlocalwindows04 May 2026
Windows HTTP.sys Elevation of Privilege Vulnerability
41RISK
open
Exploit-DB
Linksys E1200 2.0.04 - Authenticated Stack Buffer Overflow (RCE)
CVE-2025-60690HIGHhardwaremultiple04 May 2026
A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F
41RISK
open
Exploit-DB
Linux Kernel proc_readdir_de() 6.18-rc5 - Local Privilege Escalation
CVE-2025-40271HIGHlocallinux04 May 2026
fs/proc: fix uaf in proc_readdir_de()
41RISK
open
Exploit-DB
Windows 11 25H2 - Heap Overflow
CVE-2026-21248HIGHlocalwindows30 Apr 2026
Windows Hyper-V Remote Code Execution Vulnerability
41RISK
open
Exploit-DB
BusyBox 1.37.0 - Path Traversal
CVE-2026-26157HIGHwebappsmultiple30 Apr 2026
Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitization
41RISK
open
Exploit-DB
NiceGUI 3.6.1 - Path Traversal
CVE-2026-25732HIGHwebappsmultiple30 Apr 2026
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write
41RISK
open
Exploit-DB
Frigate NVR 0.16.3 - Remote Code Execution
CVE-2026-25643CRITICALwebappsmultiple30 Apr 2026
Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape
48RISK
open
Exploit-DB
HUSTOJ Zip-Slip v26.01.24 - RCE
CVE-2026-24479CRITICALwebappsmultiple30 Apr 2026
HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE
63RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.