Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
72,018 exploits
GitHub PoC
CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box
CVE-2017-7494CRITICALunder attackransomware07 Feb 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
GitHub PoC
Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)
CVE-2024-21413CRITICALunder attack07 Feb 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
PoC скрипт для CVE-2021-41773 - Path Traversal в Apache 2.4.49
CVE-2021-41773HIGHunder attackransomware07 Feb 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box
CVE-2017-7494CRITICALunder attackransomware07 Feb 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-0770CRITICALunder attack07 Feb 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-14847HIGHunder attack07 Feb 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49132CRITICAL07 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-0386HIGHunder attack07 Feb 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
initial-access
CVE-2026-1340CRITICALunder attack07 Feb 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-23550CRITICAL07 Feb 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack06 Feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
Metasploit600
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
CVE-2026-1731CRITICALunder attackransomware06 Feb 2026
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
100RISK
open
GitHub PoC
theo543/OSDS_Paper_CVE-2016-5195
CVE-2016-5195HIGHunder attack06 Feb 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Log4Shell (CVE-2021-44228) security remediation demo - Showcasing Antigravity's ability to identify and fix critical security vulnerabilities in Java applications
CVE-2021-44228CRITICALunder attackransomware05 Feb 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
CVE-2018-13379 fortiOS vulnerability POC
CVE-2018-13379CRITICALunder attackransomware05 Feb 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC
CVE-2025-32463
CVE-2025-32463CRITICALunder attack05 Feb 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2023-33107HIGHunder attack05 Feb 2026
Integer Overflow or Wraparound in Graphics Linux
71RISK
open
VulnCheck XDB
info-leak
CVE-2018-13379CRITICALunder attackransomware05 Feb 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC
Exploit for CVE-2024-46987
CVE-2024-46987HIGH05 Feb 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
GitHub PoC
CVE-2024-46987 - Camaleon CMS LFI Exploit
CVE-2024-46987HIGH05 Feb 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
GitHub PoC1
RedTeamBlueTeam/CVE-2024-5084-Red-Team
CVE-2024-5084CRITICAL05 Feb 2026
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
75RISK
open
GitHub PoC1
Exploit created using Python
CVE-2024-46987HIGH05 Feb 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
GitHub PoC
Ik0nw/CVE-2024-46987
CVE-2024-46987HIGH04 Feb 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
GitHub PoC
Evillm/CVE-2025-27520-PoC
CVE-2025-27520CRITICAL04 Feb 2026
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RISK
open
GitHub PoC
Evillm/CVE-2023-4634-PoC
CVE-2023-4634CRITICAL04 Feb 2026
Media Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
85RISK
open
Exploit-DB
Docker Desktop 4.44.3 - Unauthenticated API Exposure
CVE-2025-9074CRITICAL04 Feb 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
GitHub PoC
Evillm/CVE-2025-55182-PoC
CVE-2025-55182CRITICALunder attackransomware04 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Evillm/CVE-2025-49113-PoC
CVE-2025-49113CRITICALunder attack04 Feb 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
GitHub PoC
Evillm/CVE-2024-8856-PoC
CVE-2024-8856CRITICAL04 Feb 2026
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack04 Feb 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
previouspage 122 / 2,401next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.