Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
75,432 exploits
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack26 Jan 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
Spring Cloud Gateway SpEL RCE Vulnerability Environment
CVE-2025-41243CRITICAL26 Jan 2026
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
63RISK
open
GitHub PoC
🔍 Analyze WebKit and ANGLE vulnerabilities with this repository for CVE-2025-43529 and CVE-2025-14174, focusing on verified components and ongoing efforts.
CVE-2025-43529HIGHunder attack26 Jan 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
GitHub PoC
afifudinmtop/CVE-2009-3103
CVE-2009-310326 Jan 2026
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open
Metasploit500
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
CVE-2026-24061CRITICALunder attack26 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
Metasploit500
HUSTOJ Admin users can zip-slip problem_import_qduoj.php, planting PHP files in webroot for RCE
CVE-2026-24479CRITICAL26 Jan 2026
HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE
63RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2009-310326 Jan 2026
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISK
open
VulnCheck XDB
local
CVE-2023-3881726 Jan 2026
An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to th
23RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack26 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack26 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC1
A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9
CVE-2025-29927CRITICAL26 Jan 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC1
CVE-2025-24893 | Vulnérabilité d'exécution de code à distance sur la plateforme XWiki (preuve de concept)
CVE-2025-24893CRITICALunder attack26 Jan 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC2
This script exploits an SQL Injection vulnerability in WordPress Quiz Maker plugin (≤ 6.7.0.56) by injecting payloads via an HTTP header (default: X-Forwarded-For).
CVE-2025-10042MEDIUM25 Jan 2026
Quiz Maker <= 6.7.0.56 - Unauthenticated SQL Injection
33RISK
open
GitHub PoC
Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.
CVE-2024-3094CRITICAL25 Jan 2026
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
dionissh/CVE-2024-21413
CVE-2024-21413CRITICALunder attack25 Jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC4
POC (RCE) -> CVE-2019-9978
CVE-2019-9978MEDIUMunder attack25 Jan 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC
CVE-2025-64155
CVE-2025-64155CRITICAL25 Jan 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
60RISK
open
GitHub PoC
CVE-2025-60021
CVE-2025-60021CRITICAL25 Jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISK
open
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL25 Jan 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-33044CRITICALunder attack25 Jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack25 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC
Baza-NATO/CVE-2021-33044
CVE-2021-33044CRITICALunder attack25 Jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack25 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack25 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALunder attack25 Jan 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-20045HIGHunder attack25 Jan 2026
Cisco Unified Communications Products Remote Code Execution Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-60021CRITICAL25 Jan 2026
Apache bRPC: Remote command injection vulnerability in heap builtin service
53RISK
open
GitHub PoC2
CVE-2015-2291 Local Privilege Escalation PoC
CVE-2015-2291HIGHunder attackransomware25 Jan 2026
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RISK
open
GitHub PoC
jagg3rsec/CVE-2014-6287
CVE-2014-6287CRITICALunder attack25 Jan 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2024-21413CRITICALunder attack25 Jan 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
previouspage 134 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.