Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,777cataloged exploits
36,768CVEs with public exploitation
24,695lab-tested
79,777 exploits
GitHub PoC2
hideki233/CVE-2025-3248-Langflow-RCE
CVE-2025-3248CRITICALunder attackransomware28 Aug 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
I know you are probably here from Hack the Box, if so, yes this one actually works.
CVE-2025-55182CRITICALunder attackransomware28 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
poc and yara rules
CVE-2025-59528CRITICAL28 Aug 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
GitHub PoC
Testing CVE-2026-70463 by Fyyre
CVE-2026-70463HIGH28 Aug 2026
rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing
41RISK
open
GitHub PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
CVE-2026-73570HIGHunder attack28 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
GitHub PoC
rmhowe425/POC-CVE-2026-19295
CVE-2026-19295CRITICAL28 Aug 2026
Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
48RISK
open
VulnCheck XDB
info-leak
CVE-2024-23897CRITICALunder attackransomware28 Aug 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware28 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack28 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL28 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack28 Aug 2026
Unauthenticated Command Injection
100RISK
open
GitHub PoC
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
CVE-2026-50751CRITICALunder attackransomware28 Aug 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
GitHub PoC
Hari-v542/CVE-2026-52923
CVE-2026-52923HIGH28 Aug 2026
ipc: limit next_id allocation to the valid ID range
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack28 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-32475CRITICAL28 Aug 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open
GitHub PoC
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
CVE-2026-46339CRITICAL28 Aug 2026
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
63RISK
open
GitHub PoC
fastjson-cve-2026-16723
CVE-2026-16723CRITICAL28 Aug 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware28 Aug 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
CVE-2026-66384 - Draft or TODO
CVE-2026-66384MEDIUMunder attack28 Aug 2026
Authenticated users may write data outside the intended Docker cache path
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack28 Aug 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC
CVE-2026-65643 - Draft or TODO
CVE-2026-65643HIGH28 Aug 2026
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
41RISK
open
GitHub PoC
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
CVE-2023-27350CRITICALunder attackransomware28 Aug 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
CVE-2026-33017 PoC Reverse Shell
CVE-2026-33017CRITICALunder attack28 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC1
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
CVE-2026-33017CRITICALunder attack28 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
CVE-2026-24061CRITICALunder attack28 Aug 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
CVE-2024-23897CRITICALunder attackransomware28 Aug 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALunder attack28 Aug 2026
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
CVE-2004-268727 Aug 2026
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISK
open
GitHub PoC
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
CVE-2010-124027 Aug 2026
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RISK
open
GitHub PoC
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
CVE-2026-47851HIGH27 Aug 2026
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
21RISK
open
previouspage 10 / 2,660next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.