Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,622cataloged exploits
32,030CVEs with public exploitation
1,932lab-tested
13,187 exploits
GitHub PoC2
A Python 3 reimplementation of the classic CVE-2018-15473 OpenSSH user enumeration exploit, extended with multi-threading, wordlist support, automatic vulnerability detection, and thread-safe exploit patching.
CVE-2018-15473MEDIUM25 Mar 2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC
Intentionally vulnerable Next.js RSC Docker lab for CVE-2025-55182 (React2Shell) local testing
CVE-2025-55182CRITICALunder attackransomware25 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Advanced security research on CVE-2025-55182 (React2Shell). Features an exploitation framework with 6 functional impact scenarios (RCE to Secret Exfiltration), an interactive reverse shell, and a complete laboratory. Portfolio piece demonstrating deep analysis of Prototype Pollution and Insecure Deserialization in React Server Components
CVE-2025-55182CRITICALunder attackransomware25 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
pream-totaram/CVE-2024-52302-reproduction
CVE-2024-52302HIGH25 Mar 2026
common-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
41RISK
open
GitHub PoC
Master's Thesis research on CVE-2024-30051 (Windows DWM Heap Overflow). Features a high-reliability exploit with automated heap spray optimization, real-time logging, and empirical success-rate analysis. Portfolio piece demonstrating advanced Windows binary exploitation, heap layout manipulation, and LPE via Desktop Window Manager.
CVE-2024-30051HIGHunder attackransomware25 Mar 2026
Windows DWM Core Library Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
Static Malware Analysis of Follina (CVE-2022-30190) from Blue Team Labs Online
CVE-2022-30190HIGHunder attackransomware25 Mar 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Advanced Linux Privilege Escalation research on CVE-2021-4034 (PwnKit). Features an optimized exploit with 7 polymorphic payload modes (Interactive Shell, Backdoor, User Creation, Reverse Shell, etc). Portfolio piece focused on memory corruption logic, environment variable manipulation, and anti-forensic techniques.
CVE-2021-4034HIGHunder attack25 Mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
NeoArtemis37/OverlayFS-PrivEsc-CVE-2022-0944
CVE-2022-0944CRITICAL25 Mar 2026
Template injection in connection test endpoint leads to RCE in sqlpad/sqlpad
48RISK
open
GitHub PoC5
WinRAR < 7.13 path traversal for persistency
CVE-2025-8088HIGHunder attack25 Mar 2026
Path traversal vulnerability in WinRAR
93RISK
open
GitHub PoC
If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on Windows, and chains together a few real-world vulnerabilities — a directory traversal, a credential leak, CVE-2024-21413, and a LibreOffice macro exploit. Let's walk through it step by step.
CVE-2024-21413CRITICALunder attack25 Mar 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
PoC for CVE-2025-49596 on linux targets
CVE-2025-49596CRITICAL25 Mar 2026
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
75RISK
open
GitHub PoC
A proof-of-concept exploit demonstrating local privilege escalation to root in sudo (CVE-2025-32463) by abusing the --chroot (-R) option and injecting a malicious NSS configuration
CVE-2025-32463CRITICALunder attack25 Mar 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware analysis.
CVE-2025-21298CRITICAL24 Mar 2026
Windows OLE Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider
CVE-2026-32794MEDIUM24 Mar 2026
Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
13RISK
open
GitHub PoC
CVE-2025-55182 — React2Shell
CVE-2025-55182CRITICALunder attackransomware24 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Camera Dahua Research lỗ hổng CVE-2021-33044
CVE-2021-33044CRITICALunder attack24 Mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC
Khai thác lỗ hổng bảo mật CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware24 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Investigating CVE-2022-36804
CVE-2022-36804HIGHunder attack24 Mar 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC
rocket-panda/CVE-2025-9074
CVE-2025-9074CRITICAL23 Mar 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
GitHub PoC
CVE-2018-7422
CVE-2018-742223 Mar 2026
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RISK
open
GitHub PoC
Research-driven UPnP vulnerability scanner focusing on libupnp 1.6.19 and CVE-2012-5958.
CVE-2012-595823 Mar 2026
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RISK
open
GitHub PoC1
Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.
CVE-2025-66398CRITICAL23 Mar 2026
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
53RISK
open
GitHub PoC
폰트 인덱스 처리에서 발생하는 signed overflow 취약점
CVE-2023-21716CRITICAL22 Mar 2026
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
Lỗ hổng CVE-2025-64446 & CVE-2025-58034
CVE-2025-64446CRITICALunder attack22 Mar 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
By PrivacyHunter
CVE-2021-43798HIGHunder attack22 Mar 2026
Grafana path traversal
100RISK
open
GitHub PoC2
This repository presents a comprehensive walkthrough of the Solar Exploiting Log4j room on TryHackMe, with a focus on understanding and exploiting the critical Log4Shell vulnerability (CVE-2021-44228).The process of triggering the exploit and gaining a reverse shell is explained in a practical and easy-to-follow manner.
CVE-2021-44228CRITICALunder attackransomware22 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for educational purposes
CVE-2014-0160HIGHunder attack22 Mar 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables attackers to execute a remote code via injection of the malicious payloads into the log messages.
CVE-2021-44228CRITICALunder attackransomware22 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell vulnerability (CVE-2021-44228). The project demonstrates how attackers can leverage insecure logging mechanisms in Java applications to achieve remote code execution.
CVE-2021-44228CRITICALunder attackransomware22 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Lab & PoC
CVE-2025-53770CRITICALunder attackransomware21 Mar 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.