Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
75,432 exploits
GitHub PoC
22imer/CVE-2014-0160
CVE-2014-0160HIGHunder attack28 Jan 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map, reconstruct, and extract specific memory regions across time, not just adjacent buffers.
CVE-2014-0160HIGHunder attack28 Jan 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Very rough PoC for detecting/reproducing CVE-2022-0847 (dirty pipe) through random generation of syscalls and differential fuzzing against a model.
CVE-2022-0847HIGHunder attack28 Jan 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
GitHub PoC
CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that affected hundreds of thousands of organizations worldwide.
CVE-2021-26855CRITICALunder attackransomware28 Jan 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-2449928 Jan 2026
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
GitHub PoC
WordPress Theme Workreap 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
CVE-2021-2449928 Jan 2026
Workreap theme < 2.2.2 - Unauthenticated Upload Leading to Remote Code Execution
50RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack28 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack28 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC1
CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)
CVE-2025-43529HIGHunder attack28 Jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
Metasploit500
SolarWinds Web Help Desk unauthenticated RCE
CVE-2025-40551CRITICALunder attack28 Jan 2026
SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
95RISK
open
GitHub PoC
Clarification Regarding the Rejection Arguments
CVE-2025-56005CRITICAL28 Jan 2026
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the
53RISK
open
Metasploit500
SolarWinds Web Help Desk unauthenticated RCE
CVE-2025-40536HIGHunder attack28 Jan 2026
SolarWinds Web Help Desk Security Control Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL28 Jan 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-50498CRITICAL27 Jan 2026
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware27 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC6
This is a security exploit tool targeting CVE-2025-55182. It exploits a Remote Code Execution (RCE) vulnerability in React Server Components
CVE-2025-55182CRITICALunder attackransomware27 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
client-side
CVE-2026-21509HIGHunder attack27 Jan 2026
Microsoft Office Security Feature Bypass Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2025-54309CRITICALunder attack27 Jan 2026
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
GitHub PoC
Sn0wBaall/CVE-2024-23334-PoC
CVE-2024-23334MEDIUM27 Jan 2026
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
70RISK
open
GitHub PoC
Arguments to reject CVE-2025-56005
CVE-2025-56005CRITICAL27 Jan 2026
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the
53RISK
open
GitHub PoC1
0xLittleSpidy/CVE-2025-54309
CVE-2025-54309CRITICALunder attack27 Jan 2026
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and
100RISK
open
GitHub PoC
androidteacher/CVE-2024-50498-wpquery
CVE-2024-50498CRITICAL27 Jan 2026
WordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
75RISK
open
GitHub PoC
Simple and effective PoC for CVE-2021-43798 Grafana Path Traversal
CVE-2021-43798HIGHunder attack27 Jan 2026
Grafana path traversal
100RISK
open
GitHub PoC
An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving near-perfect theoretical rating through quantum temporal resonance and α-dispersion techniques.
CVE-2021-26855CRITICALunder attackransomware27 Jan 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack27 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-25253HIGH27 Jan 2026
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack27 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack27 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC
Looking at current high-impact vulnerabilities, let's use the VMware vCenter Server CVE-2021-21972 (CVSS 9.8) as our base. This is a publicly known RCE with patches available, perfect for demonstrating CTT enhancements.
CVE-2021-21972CRITICALunder attackransomware27 Jan 2026
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack27 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
previouspage 133 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.