Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
80,184 exploits
VulnCheck XDB
info-leak
CVE-2018-14847CRITICALunder attack20 May 2026
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC1
The code for personally reproducing the corresponding vulnerability
CVE-2026-42271HIGHunder attack20 May 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RISK
open
GitHub PoC
MGTx2/CVE-2026-39107
CVE-2026-39107MEDIUM20 May 2026
A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails
33RISK
open
GitHub PoC
Docker Container Escape POC via mlx-metal importlib
CVE-2026-5843HIGH20 May 2026
Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading
41RISK
open
GitHub PoC
Docker Container-to-Host Remote Code Execution POC via vllm-metal trust_remote_code=True
CVE-2026-5817HIGH20 May 2026
Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
41RISK
open
GitHub PoC1
VULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON
CVE-2018-14847CRITICALunder attack20 May 2026
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC
One-command scanner for the Mini Shai-Hulud npm supply-chain worm (CVE-2026-45321). Detect before rotating tokens.
CVE-2026-45321CRITICALunder attackransomware20 May 2026
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
78RISK
open
GitHub PoC
Exploit for CVE-2026-41651 - PackageKit TOCTOU Local Privilege Escalation (Pack2TheRoot)
CVE-2026-41651HIGH20 May 2026
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
41RISK
open
GitHub PoC
A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions
CVE-2026-45585MEDIUM20 May 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
GitHub PoC
a24ac1/CVE-2026-0740
CVE-2026-0740CRITICAL20 May 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC
Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and edit code injection fields.
CVE-2026-26980CRITICAL20 May 2026
Ghost has a SQL Injection in its Content API
85RISK
open
Metasploit300
Drupal Core PostgreSQL EntityQuery SQL Injection
CVE-2026-9082CRITICALunder attack20 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
julianertle/CVE-2023-0386-CTF
CVE-2023-0386HIGHunder attack20 May 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC2
PoC for PwnKit / CVE-2021-4034 - Pkexec Local Privilege Escalation
CVE-2021-4034HIGHunder attackransomware20 May 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
hyperchk/CVE-2025-24071-POC
CVE-2025-24071MEDIUM20 May 2026
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware20 May 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC2
A Go implementation of fragnesia (CVE-2026-46300)
CVE-2026-46300HIGH20 May 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware20 May 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC4
CVE-2026-42945 - NGINX Rift Toolkit
CVE-2026-42945CRITICAL20 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
Verified vulnerability journey for CVE-2025-8110 (Gogs) and CVE-2025-3248 (Langflow) — risk triage, exploitability verification, verified patches.
CVE-2025-8110HIGHunder attack20 May 2026
File overwrite in file update API in Gogs
100RISK
open
GitHub PoC
buffertrychar/CVE-2025-24071-POC
CVE-2025-24071MEDIUM20 May 2026
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
gitgudKrish/cve-2025-29927-nextjs
CVE-2025-29927CRITICAL20 May 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
CVE-2025-8110 Proof of Concept
CVE-2025-8110HIGHunder attack20 May 2026
File overwrite in file update API in Gogs
100RISK
open
GitHub PoC
Se realizó una evaluación de vulnerabilidades sobre una máquina virtual con Kali Linux utilizando un script detector para la vulnerabilidad Dirty Frag, asociada a las CVE-2026-43284 y CVE-2026-43500. Posteriormente se ejecutó un Proof of Concept (PoC) público escrito en lenguaje C para validar la posibilidad de realizar una escalada local
CVE-2026-43284HIGH20 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
Tracking PinTheft (CVE-2026-43494, CVE-2026-43502), the RDS zerocopy double-free privilege escalation
CVE-2026-43494HIGH20 May 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISK
open
GitHub PoC
POC_CVE-2026-35037
CVE-2026-35037HIGH20 May 2026
Ech0 affected by unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata
56RISK
open
VulnCheck XDB
local
CVE-2026-43500HIGH20 May 2026
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISK
open
VulnCheck XDB
local
CVE-2026-43500HIGH20 May 2026
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISK
open
GitHub PoC
CVE-2024-4367–PDF.js-xss
CVE-2024-4367MEDIUM20 May 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL20 May 2026
Authorization Bypass in Next.js Middleware
85RISK
open
previouspage 123 / 2,673next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.