Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
71,957 exploits
GitHub PoC
폰트 인덱스 처리에서 발생하는 signed overflow 취약점
CVE-2023-21716CRITICAL22 Mar 2026
Microsoft Word Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
info-leak
CVE-2021-43798HIGHunder attack22 Mar 2026
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL22 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-64446CRITICALunder attack22 Mar 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-1731CRITICALunder attackransomware22 Mar 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL22 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack21 Mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL21 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack21 Mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36991HIGH21 Mar 2026
Path Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows
61RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack21 Mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
SALMA-ESSAOUD/CVE-CVSS--CVE-2024-38063-IPv6-TCP-IP-Remote-Code-Execution-Analysis
CVE-2024-38063CRITICAL21 Mar 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to achieve root access.
CVE-2011-252321 Mar 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
Lab & PoC
CVE-2025-53770CRITICALunder attackransomware21 Mar 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
danilo1992-sys/CVE-2021-29447
CVE-2021-29447HIGH20 Mar 2026
WordPress Authenticated XXE attack when installation is running PHP 8
63RISK
open
GitHub PoC
Langflow at pre-CVE-2025-3248 fix commit for variant analysis benchmarking
CVE-2025-3248CRITICALunder attackransomware20 Mar 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
GitHub PoC
CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro
CVE-2025-6934CRITICAL20 Mar 2026
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-1492CRITICAL20 Mar 2026
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-54236CRITICALunder attack19 Mar 2026
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
GitHub PoC
SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.
CVE-2025-34096CRITICAL19 Mar 2026
Easy File Sharing HTTP Server 7.2 Buffer Overflow via POST to /sendemail.ghp
63RISK
open
GitHub PoC
havertz2110/CVE-2024-48510-PoC
CVE-2024-48510CRITICAL19 Mar 2026
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code vi
48RISK
open
GitHub PoC
POC for CVE-2021-3156 - Heap-based buffer overflow in sudo
CVE-2021-3156HIGHunder attack19 Mar 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC
Performing multiple time-based blind injections for the same character and selecting the most frequent result significantly reduces errors and improves reliability, through it is time-consuming.
CVE-2024-51482CRITICAL19 Mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC
vsftpd 2.3.4 Backdoor Exploit (CVE-2011-2523)
CVE-2011-252319 Mar 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
Exploit based in /jaiguptanick/CVE-2019-0232
CVE-2019-023219 Mar 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC
Classic stack-based buffer overflow in War FTP Daemon 1.65 demonstrating old-school remote code execution through malformed FTP commands.
CVE-2007-156719 Mar 2026
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RISK
open
GitHub PoC
Classic stack-based buffer overflow in Savant Web Server 3.1 demonstrating early-2000s remote memory corruption through a crafted HTTP request.
CVE-2002-112019 Mar 2026
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RISK
open
GitHub PoC
Classic stack-based buffer overflow in SLMail 5.1 showing how early mail servers could be compromised through oversized SMTP and POP3 commands.
CVE-2003-026419 Mar 2026
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RISK
open
GitHub PoC1
PoC Magento Session Reaper - CVE-2025-54236
CVE-2025-54236CRITICALunder attack19 Mar 2026
Adobe Commerce | Improper Input Validation (CWE-20)
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-023219 Mar 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
previouspage 103 / 2,399next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.