Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
80,095 exploits
GitHub PoC1
horrister/log4shell-cve-2021-44228
CVE-2021-44228CRITICALunder attackransomware04 Jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC2
Proof of Concept (PoC) exploit for CVE-2026-6815: Authenticated Path Traversal & Arbitrary File Write in Casdoor (< 3.54.1) leading to RCE/DoS.
CVE-2026-6815MEDIUM04 Jun 2026
CVE-2026-6815
33RISK
open
GitHub PoC
CVE-2026-23744
CVE-2026-23744CRITICAL04 Jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC10
strivepan/ActiveMQ-cve-2026-42588-scanner-gui
CVE-2026-42588HIGH04 Jun 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
41RISK
open
GitHub PoC
Dhananjayasj/CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction
CVE-2024-1698CRITICAL04 Jun 2026
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC
CVE-2026-45247 - Draft
CVE-2026-45247CRITICALunder attack04 Jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISK
open
GitHub PoC
CVE-2026-23631-Draft
CVE-2026-23631MEDIUM04 Jun 2026
redis-server Lua use-after-free may allow remote code execution
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL04 Jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
CVE-2026-35904CRITICAL04 Jun 2026
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
48RISK
open
GitHub PoC
PoC of CVE-2026-49943
CVE-2026-49943MEDIUM03 Jun 2026
CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matchi
33RISK
open
GitHub PoC
Detection script for CIFSwitch - CVE-2026-46243
CVE-2026-46243HIGH03 Jun 2026
smb: client: reject userspace cifs.spnego descriptions
41RISK
open
GitHub PoC13
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.
CVE-2026-41089CRITICAL03 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
Shcesama/cve-2023-4863-analysis
CVE-2023-4863HIGHunder attack03 Jun 2026
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC
这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。
CVE-2026-41089CRITICAL03 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
Add go CVE-2026-46300 (Fragnesia) local privilege escalation exploit
CVE-2026-46300HIGH03 Jun 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL03 Jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack03 Jun 2026
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
local
CVE-2026-43494HIGH03 Jun 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISK
open
VulnCheck XDB
local
CVE-2026-43494HIGH03 Jun 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISK
open
GitHub PoC
DanieleGiovanardi2408/cve-2024-36401-geoserver-rce
CVE-2024-36401CRITICALunder attack03 Jun 2026
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC3
Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway.
CVE-2026-0257HIGHunder attackransomware03 Jun 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open
VulnCheck XDB
local
CVE-2026-43500HIGH03 Jun 2026
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISK
open
GitHub PoC1
Rocket.Chat OAuth2 NoSQL Injection
CVE-2026-29198CRITICAL03 Jun 2026
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability c
48RISK
open
GitHub PoC
Galaxy-sc/CVE-2026-47423-dompurify-xss-detector
CVE-2026-47423HIGH03 Jun 2026
DOMPurify XSS via `selectedcontent` re-clone
41RISK
open
GitHub PoC1
Real-World Simulation: FTP Service Exploitation (ProFTPD CVE-2015-3306)
CVE-2015-330603 Jun 2026
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISK
open
GitHub PoC1
Saku0512/CVE-2026-54088-poc
CVE-2026-54088CRITICAL03 Jun 2026
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
48RISK
open
GitHub PoC6
PoC de CVE-2026-49975 (HTTP/2 Bomb): DoS remoto contra servidores web con HTTP/2 por defecto.
CVE-2026-49975HIGH03 Jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISK
open
GitHub PoC1
CVE-2025-48595 - Draft
CVE-2025-48595HIGHunder attack03 Jun 2026
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-41089CRITICAL03 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
leehunkoo/hk_CVE-2025-32433
CVE-2025-32433CRITICALunder attack03 Jun 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
previouspage 106 / 2,670next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.