Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,183cataloged exploits
37,028CVEs with public exploitation
24,695lab-tested
80,095 exploits
GitHub PoC
HAERIN-L/poc_cve-2026-42208
CVE-2026-42208CRITICALunder attack30 May 2026
LiteLLM: SQL injection in Proxy API key verification
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware30 May 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC7
CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibly disclosed to LG.
CVE-2025-38352HIGHunder attack30 May 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
GitHub PoC
CVE-2025-5947 WordPress Service Finder Bookings ≤ 6.0 Exploit
CVE-2025-5947CRITICAL30 May 2026
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-42589CRITICAL30 May 2026
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
63RISK
open
GitHub PoC
HAERIN-L/POC_CVE-2026-46716
CVE-2026-46716CRITICAL30 May 2026
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
48RISK
open
GitHub PoC1
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation
CVE-2026-8732CRITICAL30 May 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
GitHub PoC
PHP poc, exploit for CVE-2025-9074
CVE-2025-9074CRITICAL30 May 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-42208CRITICALunder attack30 May 2026
LiteLLM: SQL injection in Proxy API key verification
100RISK
open
GitHub PoC
Delt-A/CVE-2024-36401-poc
CVE-2024-36401CRITICALunder attack30 May 2026
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
GitHub PoC
CVE-2026-39987 - Draft
CVE-2026-39987CRITICALunder attack30 May 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
GitHub PoC
The ACCSvc service creates a Named Pipe with a weak Security Descriptor that allows any authenticated user to connect and send messages. When a specially crafted message (message type 0x03) is sent to the pipe, the service crashes with exit code 1067 (ERROR_PROCESS_ABORTED).
CVE-2026-9490MEDIUM30 May 2026
Acer Care Center creates a Named Pipe with a weak Security Descriptor
33RISK
open
GitHub PoC
This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.
CVE-2023-27350CRITICALunder attackransomware30 May 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
GitHub PoC
Dhananjayasj/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability
CVE-2024-21413CRITICALunder attack30 May 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
POC_CVE-2026-42589
CVE-2026-42589CRITICAL30 May 2026
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
63RISK
open
GitHub PoC
Tracking CIFSwitch (CVE-2026-46243), the CIFS cifs.spnego key-origin privilege escalation
CVE-2026-46243HIGH30 May 2026
smb: client: reject userspace cifs.spnego descriptions
41RISK
open
GitHub PoC3
CVE-2026-0257
CVE-2026-0257HIGHunder attackransomware30 May 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open
VulnCheck XDB
local
CVE-2025-38352HIGHunder attack30 May 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
GitHub PoC
Testing a List of IP address incase they are vulnerable to CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware30 May 2026
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
SourceCodester Pharmacy Sales and Inventory System 1.0 - Vulnerable source code for CVE-2026-7392 SQL Injection
CVE-2026-7392MEDIUM30 May 2026
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 May 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
GitHub PoC
CVE-2025-10162 Exploit
CVE-2025-10162HIGH30 May 2026
OrderConvo < 14 - Unauthenticated Arbitrary File Read
56RISK
open
GitHub PoC2
Exploiting heap-based buffer overflow in sudo for privilege escalation
CVE-2021-3156HIGHunder attack30 May 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-5947CRITICAL30 May 2026
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 May 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
GitHub PoC
Dungsocool/CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware30 May 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 May 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
GitHub PoC
Technical report about CVE-2022-22947 in Spring Cloud Gateway and its exploitation through exposed Actuator endpoints.
CVE-2022-22947CRITICALunder attack29 May 2026
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RISK
open
GitHub PoC
Exploit de Execução Remota de Código (RCE) no XWiki
CVE-2025-24893CRITICALunder attack29 May 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
Exploit-DB
CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
CVE-2026-44376MEDIUMwebappsmultiple29 May 2026
CubeCart: Reflected XSS in Store Search Bar
33RISK
open
previouspage 111 / 2,670next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.