Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
71,957 exploits
GitHub PoC1
Ni8mare, n8n RCE
CVE-2026-21858CRITICAL11 Feb 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
GitHub PoC
Cisco iOS SNMP Overflow Exploit Toolkit (CVE-2017-6736)
CVE-2017-6736HIGHunder attack11 Feb 2026
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RISK
open
GitHub PoC3
PoC exploit for CVE-2025-49132 (GHSA-24wv-6c99-f843) – Unauthenticated Remote Code Execution in Pterodactyl Panel ≤ 1.11.10
CVE-2025-49132CRITICAL11 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
GitHub PoC1
This script exploits Remote Code Execution vulnerability in Pterodactyl Panel < 1.11.11
CVE-2025-49132CRITICAL11 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
GitHub PoC
PowerShell remediation for CVE-2013-3900 (WinVerifyTrust) / Tenable Plugin 166555 using EnableCertPaddingCheck.
CVE-2013-3900MEDIUMunder attack11 Feb 2026
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC
This is a modified version of the time-based SQL injection exploit for CMS Made Simple <= 2.2.9. The exploit was originally created by Daniele Scanu and has been updated for better compatibility and modern Python practices.
CVE-2019-905311 Feb 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC4
This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will search for and download any SSH key or variation of keys to the local computer. This program also performs the CVE-2021-41773_ apache2.4.49 and 50 traversal path exploit. In addtion to other LFI Vuln
CVE-2021-41773HIGHunder attackransomware11 Feb 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
ISabbiI/PoC-Apache-CVE-2021-41773-Infrastructure-LAB
CVE-2021-41773HIGHunder attackransomware11 Feb 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-53770CRITICALunder attackransomware11 Feb 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Scanner for the SharePoint CVE-2025-53770 RCE zero day vulnerability (fork from hazcod/CVE-2025-53770)
CVE-2025-53770CRITICALunder attackransomware11 Feb 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL11 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL11 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL11 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
GitHub PoC
Ahmedf000/CVE-2025-49132_HTB_SEASON10
CVE-2025-49132CRITICAL11 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH11 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-1357CRITICAL11 Feb 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISK
open
Exploit-DB
motionEye 0.43.1b4 - RCE
CVE-2025-60787HIGH11 Feb 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-21858CRITICAL11 Feb 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-8088HIGHunder attack11 Feb 2026
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
initial-access
CVE-2025-5394CRITICAL11 Feb 2026
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
75RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Feb 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CVE-2025-62215 exploit development using Claude Code Agent Team
CVE-2025-62215HIGHunder attack11 Feb 2026
Windows Kernel Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
Wise-Security/CVE-2025-69600
CVE-2025-69600HIGH11 Feb 2026
Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execut
41RISK
open
GitHub PoC
openshift rce poc
CVE-2024-7387CRITICAL11 Feb 2026
Openshift/builder: path traversal allows command injection in privileged buildcontainer using docker build strategy
48RISK
open
GitHub PoC1
George0Papasotiriou/CVE-2025-15556-Notepad-WinGUp-Updater-RCE
CVE-2025-15556HIGHunder attack10 Feb 2026
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
71RISK
open
GitHub PoC1
George0Papasotiriou/CVE-2025-59470-PostgreSQL-Command-Injection
CVE-2025-59470CRITICAL10 Feb 2026
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal
48RISK
open
VulnCheck XDB
client-side
CVE-2018-7600CRITICALunder attackransomware10 Feb 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
faysalferdous/CVE-2025-68645-Exploiting-Zimbra-Webmail-LFI-Vulnerability
CVE-2025-68645HIGHunder attack10 Feb 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
GitHub PoC
Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).
CVE-2024-21413CRITICALunder attack10 Feb 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC3
CVE-2025-54253 | CVE-2025-54254 | Adobe Experience Manager Forms XXE → RCE Framework
CVE-2025-54253CRITICALunder attack10 Feb 2026
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISK
open
previouspage 118 / 2,399next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.