Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,026cataloged exploits
32,224CVEs with public exploitation
1,932lab-tested
72,030 exploits
VulnCheck XDB
initial-access
CVE-2025-2294CRITICAL23 Jan 2026
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC
Dirty Cow exploit - CVE-2016-5195
CVE-2016-5195HIGHunder attack22 Jan 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Relatório TryHackMe — n8n CVE-2025-68613 (CVSS 9.9)
CVE-2025-68613CRITICALunder attack22 Jan 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
CVE-2021-4034HIGHunder attack22 Jan 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2023-51409. Abuses an arbitrary file upload flaw in the AI Engine WordPress plugin to upload a PHP webshell and achieve remote command execution without authentication, including OS detection and an interactive shell.
CVE-2023-51409CRITICAL22 Jan 2026
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISK
open
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute arbitrary PHP code, write a web shell to the uploads directory, detect the target operating system, and achieve remote command execution via an interactive shell.
CVE-2024-50498CRITICAL22 Jan 2026
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack22 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack22 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack22 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attack22 Jan 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2024-51793. Exploits an arbitrary file upload vulnerability via admin-ajax.php to upload a PHP payload and achieve remote command execution on vulnerable WordPress installations, including OS detection and an interactive command shell.
CVE-2024-51793CRITICAL22 Jan 2026
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-51409CRITICAL22 Jan 2026
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack22 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack22 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-50498CRITICAL22 Jan 2026
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack22 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC13
Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security WordPress plugin to impersonate an admin user, upload a malicious plugin, and achieve remote command execution via an interactive shell.
CVE-2024-10924CRITICAL22 Jan 2026
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
GitHub PoC1
Exploit for CVE-2023-40028 (for educational purposes)
CVE-2023-40028MEDIUM22 Jan 2026
Arbitrary file read via symlinks in Ghost
45RISK
open
GitHub PoC2
Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to upload a remote PHP payload, detect the target operating system, and achieve remote command execution through an interactive web shell.
CVE-2024-9932CRITICAL22 Jan 2026
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-10924CRITICAL22 Jan 2026
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL22 Jan 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack22 Jan 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC2
CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware22 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823.
CVE-2012-1823CRITICALunder attack22 Jan 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
GitHub PoC
MOVEit Transfer 2023 mass data breach (CVE-2023-34362)
CVE-2023-34362CRITICALunder attackransomware21 Jan 2026
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
GitHub PoC
abanop22333/Apache-Authentication-Flaw-Research-CVE-2024-38476-
CVE-2024-38476CRITICAL21 Jan 2026
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
60RISK
open
GitHub PoC
CybersRMUTL/CVE-2019-10149-Exim4-RCE
CVE-2019-10149CRITICALunder attack21 Jan 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC2
This Poc demonstrate Arbitrary read/write primitives provided by CVE-2025-7771
CVE-2025-7771HIGH21 Jan 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2017-7921CRITICALunder attack21 Jan 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC2
海康威视RCE漏洞 批量检测和利用工具
CVE-2021-36260CRITICALunder attack21 Jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
previouspage 128 / 2,401next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.