Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
8,829 exploits
VulnCheck XDB
initial-access
CVE-2022-4288915 Jul 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-58138CRITICAL15 Jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-58138CRITICAL15 Jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
VulnCheck XDB
local
CVE-2023-36802HIGHunder attack15 Jul 2026
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2026-49049HIGH14 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISK
open
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL14 Jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-3864614 Jul 2026
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL14 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
info-leak
CVE-2023-25157CRITICAL13 Jul 2026
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-56291CRITICALunder attack13 Jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISK
open
VulnCheck XDB
initial-access
CVE-2022-2907813 Jul 2026
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware12 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-4631CRITICAL12 Jul 2026
Cockpit: cockpit: unauthenticated remote code execution due to ssh command-line argument injection
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-20127CRITICALunder attack12 Jul 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
local
CVE-2023-4911HIGHunder attack12 Jul 2026
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-023212 Jul 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
VulnCheck XDB
initial-access
CVE-2019-023212 Jul 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-2564611 Jul 2026
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-14894CRITICAL11 Jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL11 Jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL11 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
local
CVE-2026-46331HIGH11 Jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
VulnCheck XDB
info-leak
CVE-2021-43798HIGHunder attack11 Jul 2026
Grafana path traversal
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1003030CRITICALunder attack11 Jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-56291CRITICALunder attack11 Jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack11 Jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
VulnCheck XDB
initial-access
CVE-2022-2907811 Jul 2026
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[
50RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware11 Jul 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.