Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

74,469cataloged exploits
34,020CVEs with public exploitation
19,614lab-tested
74,469 exploits
GitHub PoC
Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive suite—featuring multi-vector rotations, HTTP/2 Rapid Reset (CVE-2023-44487) exploitation, and mTLS 1.3-encrypted C2 orchestration—with a high-integrity 7-Tier Blue Elite Teaming defense-in-depth architecture.
CVE-2023-44487HIGHunder attack18 Jan 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
Exploit-DB
Siklu EtherHaul Series EH-8010 - Remote Command Execution
CVE-2025-57174CRITICAL17 Jan 2026
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and p
48RISK
open
VulnCheck XDB
client-side
CVE-2024-46982HIGH17 Jan 2026
Cache Poisoning in next.js
53RISK
open
GitHub PoC
Comprehensive 100% Unrestricted Technical Analysis of JAGUAR_TOOTH Malware (APT28). High-precision reconstruction of Cisco IOS SNMP exploitation, ROP chaining, and memory-resident espionage tactics by SASTRA_ADI_WIGUNA.
CVE-2017-6742HIGHunder attack17 Jan 2026
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the aff
76RISK
open
GitHub PoC
Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.
CVE-2019-905317 Jan 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALunder attack17 Jan 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-23550CRITICAL17 Jan 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open
GitHub PoC1
Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521)
CVE-2026-46368HIGH16 Jan 2026
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
41RISK
open
GitHub PoC
A simple Python proof-of-concept tool to check for Apache path traversal vulnerability (CVE-2021-41773). Detects vulnerable server versions and verifies exploitation by probing sensitive files. Built for learning CVE analysis, not mass exploitation.
CVE-2021-41773HIGHunder attackransomware16 Jan 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
faisha1311/React2Shell-CVE-2025-55182-TryHackMe
CVE-2025-55182CRITICALunder attackransomware16 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware16 Jan 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack16 Jan 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-22515CRITICALunder attackransomware16 Jan 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a Metasploitable 2 machine with a reverse shell to access the root folder. Once this folder has been accessed, it should reveal the /etc/shadow folder which would give proof of compromise.
CVE-2007-244716 Jan 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC1
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-specific attacks (CVE-2022-21449, CVE-2018-0114).
CVE-2018-011416 Jan 2026
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open
GitHub PoC
dkq-k/cve-2023-22515-1
CVE-2023-22515CRITICALunder attackransomware16 Jan 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC
This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known post-exploitation IOCs.
CVE-2025-20393CRITICALunder attack16 Jan 2026
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
83RISK
open
GitHub PoC
dkq-k/CVE-2023-22515
CVE-2023-22515CRITICALunder attackransomware16 Jan 2026
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RISK
open
GitHub PoC2
LuemmelSec/CVE-2025-59287---WSUS-SCCM-RCE
CVE-2025-59287CRITICALunder attack16 Jan 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
End-to-end remediation of CVE-2013-3900 using PowerShell and Tenable. Demonstrates vulnerability identification, registry hardening, and automated verification in an Azure environment
CVE-2013-3900MEDIUMunder attack16 Jan 2026
WinVerifyTrust Signature Validation Vulnerability
75RISK
open
GitHub PoC
Kai-One001/React-Router-CVE-2025-61686-
CVE-2025-61686CRITICAL16 Jan 2026
React Router has Path Traversal in File Session Storage
53RISK
open
GitHub PoC
CVE-2025-61686复现的dockerfile与poc
CVE-2025-61686CRITICAL15 Jan 2026
React Router has Path Traversal in File Session Storage
53RISK
open
GitHub PoC1
Authorized high-impact tool from CYBERDUDEBIVASH ECOSYSTEM to detect CVE-2025-64155 (FortiSIEM phMonitor Command Injection). Scans for open ports and vulnerable behaviors ethically.
CVE-2025-64155CRITICAL15 Jan 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RISK
open
GitHub PoC
CVE-2025-11953 - The React Native Metro server's default external binding exposes a vulnerable endpoint, allowing unauthenticated attackers to execute arbitrary OS commands via a malicious POST request.
CVE-2025-11953CRITICALunder attack15 Jan 2026
Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests
90RISK
open
GitHub PoC
shubtheone/CVE-2021-36260-hikvision
CVE-2021-36260CRITICALunder attack15 Jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC
A stored Cross‑Site Scripting vulnerability exists in xxl-job-admin JobInfoController.java where the addressList parameter accepts unsanitized URL‑encoded JavaScript. The payload is stored and later executed in users’ browsers, lead unauthorized actions.
CVE-2026-26719MEDIUM15 Jan 2026
Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra
33RISK
open
GitHub PoC2
Phantom Signature Attack: An Analysis of the Critical Vulnerability CVE-2025-29774 in the Bitcoin Protocol, SIGHASH_SINGLE Implementation Flaws, and the Mathematical Framework for Private Key Recovery in Lost Cryptocurrency Wallets Enabling Unrestricted Control over BTC Assets
CVE-2025-29774CRITICAL15 Jan 2026
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
48RISK
open
GitHub PoC
🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.
CVE-2025-14847HIGHunder attack15 Jan 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
GitHub PoC
BOSE122/CVE-2024-3094
CVE-2024-3094CRITICAL15 Jan 2026
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack15 Jan 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
previouspage 131 / 2,483next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.