Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

72,034cataloged exploits
32,227CVEs with public exploitation
1,932lab-tested
72,041 exploits
VulnCheck XDB
initial-access
CVE-2023-51409CRITICAL22 Jan 2026
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISK
open
GitHub PoC
Relatório TryHackMe — n8n CVE-2025-68613 (CVSS 9.9)
CVE-2025-68613CRITICALunder attack22 Jan 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC1
A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823.
CVE-2012-1823CRITICALunder attack22 Jan 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
GitHub PoC
Dirty Cow exploit - CVE-2016-5195
CVE-2016-5195HIGHunder attack22 Jan 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC2
CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware22 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2017-7921CRITICALunder attack21 Jan 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
GitHub PoC
CybersRMUTL/CVE-2019-10149-Exim4-RCE
CVE-2019-10149CRITICALunder attack21 Jan 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC2
海康威视RCE漏洞 批量检测和利用工具
CVE-2021-36260CRITICALunder attack21 Jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC
SMBv1: CVE-2017-0143, gravedad 8.8, de ejecucion remota de codigo (RCE), en Windows con SMBv1 (ms17-010)
CVE-2017-0143HIGHunder attackransomware21 Jan 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
MOVEit Transfer 2023 mass data breach (CVE-2023-34362)
CVE-2023-34362CRITICALunder attackransomware21 Jan 2026
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-919321 Jan 2026
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALunder attack21 Jan 2026
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC
afifudinmtop/CVE-2021-21425
CVE-2021-21425CRITICAL21 Jan 2026
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISK
open
GitHub PoC
CybersRMUTL/CVE-2019-9193-Postgresql-RCE
CVE-2019-919321 Jan 2026
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RISK
open
GitHub PoC1
CVE-2017-7921, CVE-2021-36260 updated 21/01/2026
CVE-2021-36260CRITICALunder attack21 Jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL21 Jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISK
open
GitHub PoC
nimesh895/Malware-Analysis-Follina-CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware21 Jan 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
InfoSecAntara/CVE-2025-14847-MongoDB
CVE-2025-14847HIGHunder attack21 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC1
Final Project in Fundamental network security,POC CVE-202438063
CVE-2024-38063CRITICAL21 Jan 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory.
CVE-2025-61686CRITICAL21 Jan 2026
React Router has Path Traversal in File Session Storage
53RISK
open
GitHub PoC
abanop22333/Apache-Authentication-Flaw-Research-CVE-2024-38476-
CVE-2024-38476CRITICAL21 Jan 2026
Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
60RISK
open
GitHub PoC2
This Poc demonstrate Arbitrary read/write primitives provided by CVE-2025-7771
CVE-2025-7771HIGH21 Jan 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
VulnCheck XDB
local
CVE-2023-52271MEDIUM21 Jan 2026
The wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process
33RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack21 Jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL20 Jan 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-54068CRITICALunder attack20 Jan 2026
Livewire vulnerable to remote command execution during property update hydration
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL20 Jan 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack20 Jan 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL20 Jan 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
GitHub PoC8
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.
CVE-2026-23744CRITICAL20 Jan 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
previouspage 129 / 2,402next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.