Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
72,018 exploits
GitHub PoC
Evillm/CVE-2025-27520-PoC
CVE-2025-27520CRITICAL04 Feb 2026
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
75RISK
open
GitHub PoC
Evillm/CVE-2025-49113-PoC
CVE-2025-49113CRITICALunder attack04 Feb 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware04 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-49113CRITICALunder attack04 Feb 2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack03 Feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
info-leak
CVE-2023-27163MEDIUM03 Feb 2026
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack03 Feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC2
A Firefox extension for detecting React2Shell vulnerabilities (CVE-2025-55182 & CVE-2025-66478) in web applications.
CVE-2025-55182CRITICALunder attackransomware03 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
aditidutta696-dev/Spring4Shell-CVE-2022-22965-Exploitation-Attempt
CVE-2022-22965CRITICALunder attack03 Feb 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC2
Professional exploit for CVE-2024-28397: Js2Py Sandbox Escape leading to Remote Code Execution (RCE). Includes modular payload generation.
CVE-2024-28397MEDIUM03 Feb 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC
Path Traversal vulnerability
CVE-2024-46987HIGH03 Feb 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
GitHub PoC
🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.
CVE-2026-24061CRITICALunder attack03 Feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC
CVE-2025-65791 — Command Injection in ZoneMinder
CVE-2025-65791CRITICAL03 Feb 2026
ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i
48RISK
open
GitHub PoC1
Spydomain/CVE-2017-1000112-PoC
CVE-2017-100011202 Feb 2026
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RISK
open
VulnCheck XDB
local
CVE-2021-22555HIGHunder attack02 Feb 2026
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack02 Feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack02 Feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-58360HIGHunder attack02 Feb 2026
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack02 Feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware02 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Spydomain/CVE-2021-22555-Poc
CVE-2021-22555HIGHunder attack02 Feb 2026
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RISK
open
GitHub PoC
CVE-2025-32433-available-for-windows
CVE-2025-32433CRITICALunder attack02 Feb 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
GitHub PoC1
thomas-osgood/cve-2025-58360
CVE-2025-58360HIGHunder attack02 Feb 2026
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
98RISK
open
GitHub PoC1
[우리 FISA] 기술 세미나 우승 - 클라우드 서비스 개발 6기 3팀 - React2Shell (CVE-2025-55182) 분석 및 연구
CVE-2025-55182CRITICALunder attackransomware02 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC27
This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive server files via the MediaController. Intended for authorized security auditing and educational research only.
CVE-2024-46987HIGH01 Feb 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
GitHub PoC17
Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.
CVE-2025-43529HIGHunder attack01 Feb 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
GitHub PoC
Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability
CVE-2025-29927CRITICAL01 Feb 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Dirty COW Privilege Escalation (CVE-2016-5195)
CVE-2016-5195HIGHunder attack01 Feb 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC3
Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)
CVE-2022-0847HIGHunder attack01 Feb 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack01 Feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
previouspage 123 / 2,401next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.