Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
8,843 exploits
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL17 Apr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack17 Apr 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM17 Apr 2026
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-8110HIGHunder attack17 Apr 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL16 Apr 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL16 Apr 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-49113CRITICALunder attack16 Apr 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack16 Apr 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
local
CVE-2024-30088HIGHunder attackransomware16 Apr 2026
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2024-42009CRITICALunder attack16 Apr 2026
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL15 Apr 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL15 Apr 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack15 Apr 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-1357CRITICAL15 Apr 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
local
CVE-2024-26229HIGH15 Apr 2026
Windows CSC Service Elevation of Privilege Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-39808CRITICALunder attack15 Apr 2026
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack14 Apr 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack14 Apr 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-24000HIGH14 Apr 2026
WordPress Post SMTP plugin <= 3.2.0 - Account Takeover Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware14 Apr 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-29357CRITICALunder attackransomware13 Apr 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL13 Apr 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack13 Apr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware13 Apr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL13 Apr 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-8110HIGHunder attack13 Apr 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL13 Apr 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL12 Apr 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-59528CRITICAL12 Apr 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack12 Apr 2026
File overwrite in file update API in Gogs
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.