Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,018cataloged exploits
32,219CVEs with public exploitation
1,932lab-tested
72,018 exploits
GitHub PoC17
Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.
CVE-2025-43529HIGHunder attack01 Feb 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
GitHub PoC
React2shell exploit (CVE-2025-55182+CVE-2025-66478)
CVE-2025-55182CRITICALunder attackransomware31 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack31 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC
Superproject repo for Backup Exec CVE-2025-48384 exploit
CVE-2025-48384HIGHunder attack31 Jan 2026
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware31 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CVE-2025-40554 Exploitation
CVE-2025-40554CRITICAL31 Jan 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISK
open
GitHub PoC
Superproject repo for Backup Exec CVE-2024-32002 exploit
CVE-2024-32002CRITICAL31 Jan 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
GitHub PoC
Submodule repo for Backup Exec CVE-2024-32002 exploit
CVE-2024-32002CRITICAL31 Jan 2026
Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
53RISK
open
VulnCheck XDB
client-side
CVE-2025-48384HIGHunder attack31 Jan 2026
Git allows arbitrary code execution through broken config quoting
71RISK
open
VulnCheck XDB
local
CVE-2026-21858CRITICAL30 Jan 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
GitHub PoC3
1atakan1/CVE-2025-6934
CVE-2025-6934CRITICAL30 Jan 2026
Opal Estate Pro <= 1.7.5 - Unauthenticated Privilege Escalation via 'on_regiser_user'
68RISK
open
GitHub PoC
afifudinmtop/CVE-2021-43857-Gerapy-v0.9.7
CVE-2021-43857CRITICAL30 Jan 2026
Gerapy may contain remote code execution vulnerability
60RISK
open
GitHub PoC1
webkit_refraction.js (The 33-Layer WebGL Payload) ​This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It induces the Use-After-Free (UAF) in CVE-2025-43529 by desynchronizing the WebKit garbage collector from the GPU's Metal command buffer.
CVE-2025-43529HIGHunder attack30 Jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack30 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
Metasploit600
Ivanti Endpoint Manager Mobile (EPMM) unauthenticated RCE
CVE-2026-1281CRITICALunder attack29 Jan 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISK
open
VulnCheck XDB
client-side
CVE-2025-40554CRITICAL29 Jan 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISK
open
Metasploit600
Ivanti Endpoint Manager Mobile (EPMM) unauthenticated RCE
CVE-2026-1340CRITICALunder attack29 Jan 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISK
open
Metasploit600
Tactical RMM Jinja2 SSTI Remote Code Execution
CVE-2025-69516HIGH29 Jan 2026
A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica
36RISK
open
GitHub PoC
Metasploitable 2 üzerinde vsftpd 2.3.4 (CVE-2011-2523) zafiyetinin istismarı ve sızma sonrası adımlarını içeren laboratuvar çalışması.
CVE-2011-252329 Jan 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
HP Power Manager 4.2 (Build 7) exploit
CVE-2009-399929 Jan 2026
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RISK
open
GitHub PoC
Proof of concept for CVE-2019-11707
CVE-2019-11707HIGHunder attack29 Jan 2026
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISK
open
GitHub PoC30
An uninitialized read vulnerability by incorrect Turboshaft Store-Store Elimination in V8.
CVE-2025-5419HIGHunder attack29 Jan 2026
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISK
open
GitHub PoC
CVE-2020-11107-Local-Privilege-Escalation-XAMPP-7.2.29-7.3.x-7.3.16-7.4.x-7.4.4
CVE-2020-1110729 Jan 2026
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
28RISK
open
GitHub PoC1
imbas007/auth-bypass-CVE-2025-40554
CVE-2025-40554CRITICAL29 Jan 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISK
open
VulnCheck XDB
info-leak
CVE-2025-5419HIGHunder attack29 Jan 2026
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl
71RISK
open
VulnCheck XDB
initial-access
CVE-2019-11707HIGHunder attack29 Jan 2026
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RISK
open
GitHub PoC
deepankarkumar1/CVE-2025-55182_Vulnerable-Application
CVE-2025-55182CRITICALunder attackransomware29 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)
CVE-2025-43529HIGHunder attack28 Jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
GitHub PoC
22imer/CVE-2014-0160
CVE-2014-0160HIGHunder attack28 Jan 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map, reconstruct, and extract specific memory regions across time, not just adjacent buffers.
CVE-2014-0160HIGHunder attack28 Jan 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
previouspage 124 / 2,401next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.