Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
80,095 exploits
GitHub PoC
Automated defect verification tool for 6 dnsmasq CVEs (CVE-2026-2291, 4890, 4891, 4892, 4893, 5172)
CVE-2026-2291HIGH01 Jun 2026
CVE-2026-2291
41RISK
open
GitHub PoC1
Exploits the CVE-2026-0257 vulnerability by forging a GlobalProtect authentication override cookie using the TLS server's public key.
CVE-2026-0257HIGHunder attackransomware01 Jun 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open
GitHub PoC
CVE-2026-8732 - Draft (WordPress)
CVE-2026-8732CRITICAL01 Jun 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
GitHub PoC
Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization
CVE-2026-27886CRITICAL01 Jun 2026
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
48RISK
open
GitHub PoC8
p3Nt3st3r-sTAr/CVE-2026-8732-POC
CVE-2026-8732CRITICAL01 Jun 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
GitHub PoC
CVE-2026-24061 — GNU InetUtils Telnetd Authentication Bypass Scanner
CVE-2026-24061CRITICALunder attack01 Jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC2
DeepSecurityResearch/CVE-2026-2586
CVE-2026-2586CRITICAL01 Jun 2026
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
48RISK
open
GitHub PoC
CVE analysis of CVE-2025-40536, SolarWinds Web Help Desk security control bypass (CVSS 8.1). Covers vulnerability mechanics, attack chain with companion RCE CVEs, Storm-2603 threat actor attribution, MITRE ATT&CK mapping, and detection/remediation guidance for DoD and government environments.
CVE-2025-40536HIGHunder attack01 Jun 2026
SolarWinds Web Help Desk Security Control Bypass Vulnerability
100RISK
open
Exploit-DB
WordPress OrderConvo 14 - Path Traversal
CVE-2025-10162HIGHwebappsmultiple01 Jun 2026
OrderConvo < 14 - Unauthenticated Arbitrary File Read
56RISK
open
GitHub PoC
A Go implementation of fragnesia (CVE-2026-46300)
CVE-2026-46300HIGH01 Jun 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL01 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack01 Jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC1
A Go implementation of dirtyfrag (CVE-2026-43284 / CVE-2026-43500)
CVE-2026-43284HIGH01 Jun 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
CVE-2026-9560 - Draft
CVE-2026-9560CRITICAL01 Jun 2026
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware31 May 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Dungsocool/CVE-2014-3120
CVE-2014-3120HIGHunder attack31 May 2026
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open
GitHub PoC
Jeanback1/CVE-2019-9053-exploit
CVE-2019-905331 May 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
info-leak
CVE-2024-38475CRITICALunder attack31 May 2026
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
GitHub PoC
kavin-jindal/CVE-2026-48800-PoC
CVE-2026-48800HIGH31 May 2026
Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-6553CRITICAL31 May 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
GitHub PoC
Jeanback1/CVE-2019-0211-exploit
CVE-2019-0211HIGHunder attack31 May 2026
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 May 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
CVE-2024-38475 exploitation & scanning tool with Mullvad VPN rotation
CVE-2024-38475CRITICALunder attack31 May 2026
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
GitHub PoC
CVE-2026-8836 — lwIP SNMPv3 stack-based buffer overflow PoC (CVSS 9.8)
CVE-2026-8836CRITICAL31 May 2026
lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow
48RISK
open
VulnCheck XDB
initial-access
CVE-2014-3120HIGHunder attack31 May 2026
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RISK
open
VulnCheck XDB
local
CVE-2019-0211HIGHunder attack31 May 2026
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RISK
open
GitHub PoC
b1nhack/CVE-2024-1086
CVE-2024-1086HIGHunder attackransomware31 May 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC1
An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and compliance reporting for CVE-2021-44228 (Log4Shell).
CVE-2021-44228CRITICALunder attackransomware31 May 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 May 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 May 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
previouspage 109 / 2,670next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.