Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
80,184 exploits
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL22 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-894222 May 2026
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC1
Python exploit toolkit for WordPress Crop Image RCE — CVE-2019-8942 & CVE-2019-8943
CVE-2019-894222 May 2026
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL22 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-20182CRITICALunder attack22 May 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-5281HIGHunder attack22 May 2026
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RISK
open
GitHub PoC
NullByte8080/CVE-2026-36228
CVE-2026-36228HIGH22 May 2026
Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu
41RISK
open
GitHub PoC
jaf0rk/CVE-2026-5281
CVE-2026-5281HIGHunder attack22 May 2026
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack22 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-42945CRITICAL22 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
Portable Python PoC for CVE-2026-31431 (Copy Fail)
CVE-2026-31431HIGHunder attack22 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack21 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
CVE-2026-45829
CVE-2026-45829CRITICAL21 May 2026
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack21 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack21 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC2
CVE-2026-9082 | SA-CORE-2026-004
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC1
PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
Synthetic demo target for EXPOSURE — CVE-2018-21268 (traceroute) + CVE-2018-3757 (pdf-image)
CVE-2018-21268CRITICAL21 May 2026
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host para
48RISK
open
GitHub PoC3
0xFuffM3/CVE-2026-31635-DirtyDecrypt
CVE-2026-31635HIGH21 May 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISK
open
GitHub PoC2
Langflow Arbitrary Directory Deletion
CVE-2026-42048CRITICAL21 May 2026
Langflow: Path Traversal in Langflow Knowledge Bases API
48RISK
open
Exploit-DB
FUXA 1.2.9 - RCE
CVE-2026-25895CRITICALwebappsmultiple21 May 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RISK
open
GitHub PoC
ercihan/CVE-2026-40369
CVE-2026-40369HIGH21 May 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC4
PoC for CVE-2024-6678
CVE-2024-6678CRITICAL21 May 2026
Authentication Bypass by Spoofing in GitLab
48RISK
open
GitHub PoC
EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps
CVE-2013-181421 May 2026
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RISK
open
GitHub PoC1
More portable POC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux
CVE-2026-31431HIGHunder attack21 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
Exploit-DB
Cockpit 359 - RCE
CVE-2026-4631CRITICALwebappsmultiple21 May 2026
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
68RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware21 May 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Scanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.
CVE-2024-6387HIGH21 May 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
CVE-2026-9082
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
Metasploit300
Concrete CMS Unauthenticated File Usage Disclosure
CVE-2026-6826MEDIUM21 May 2026
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
28RISK
open
previouspage 121 / 2,673next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.