Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
80,184 exploits
GitHub PoC1
Full-chain exploit for CVE-2025-2783 (Ipcz Sandbox Escape & RCE).
CVE-2025-2783HIGHunder attack08 May 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open
GitHub PoC1
Remote Code Execution in Alexantr filemanager v1.0 via unrestricted file upload
CVE-2026-37637CRITICAL08 May 2026
An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php compon
48RISK
open
GitHub PoC
Bannt08/Research-CVE-2026-21858
CVE-2026-21858CRITICAL08 May 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
GitHub PoC
Morton-Li/copy-fail-CVE-2026-31431
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC2
Vulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500)
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC6
Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl
CVE-2026-23918HIGH08 May 2026
Apache HTTP Server: http2: double free and possible RCE on early reset
53RISK
open
GitHub PoC
Sidjaz/CrushFTP-CVE-2024-4040-Proof-of-Concept
CVE-2024-4040CRITICALunder attack08 May 2026
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-4040CRITICALunder attack08 May 2026
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RISK
open
GitHub PoC
Paranoid disable Linux IPsec ESP support (esp4/esp6) and RxRPC support.
CVE-2026-43284HIGH08 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE
CVE-2022-30190HIGHunder attackransomware08 May 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC18
A proof-of-concept demonstrating how a default, unprivileged Kubernetes Pod can achieve node-level code execution on Amazon EKS by exploiting the Dirty Frag (CVE-2026-43284) Linux kernel page-cache corruption vulnerability through shared container image layers.
CVE-2026-43284HIGH08 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC1
CVE-2026-31431 in C for aarch64 and amd64
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
A fully refactored, Python 3 compatible exploit script for Tomcat Ghostcat (CVE-2020-1938 / CNVD-2020-10487) AJP Local File Inclusion
CVE-2020-1938CRITICALunder attack08 May 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
branixsolutions/Security-CVE-2026-41940-cPanel-WHM-WP2
CVE-2026-41940CRITICALunder attackransomware08 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC1
azqzazq1/CVE-2026-7867-disk2root
CVE-2026-7867HIGH08 May 2026
Udisks2: udisks2: local privilege escalation via as-user option spoofing
41RISK
open
VulnCheck XDB
client-side
CVE-2025-2783HIGHunder attack08 May 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open
GitHub PoC
Kernel LPE PoC & Mitigation Toolkit - ROSN-LR5-Full (CVE-2026-31431)
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Linux Kernel Local Privilege Escalation
CVE-2026-31431HIGHunder attack08 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack08 May 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC1
kyukazamiqq/cve-2026-5718
CVE-2026-5718HIGH08 May 2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISK
open
GitHub PoC
Xmyronn/CVE-2026-10243-AUTH
CVE-2026-10243MEDIUM08 May 2026
code-projects Smart Parking System Admin Endpoint missing authentication
33RISK
open
GitHub PoC
Desc "Fix Redis CVE ultil 20260508-10h51 GMT+7"
CVE-2026-25589HIGH08 May 2026
RedisBloom RESTORE invalid memory access may allow remote code execution
21RISK
open
GitHub PoC
CTT-Enhanced Apache mod_auth_digest Timing Attack — CVE-2026-33006 Remote Digest Authentication Bypass → 33-Layer Temporal Timing Attack Original vulnerability: Apache HTTP Server 2.4.66 (mod_auth_digest timing leak) CTVSS (Original): 4.8 (Medium) CTT-Enhanced CVSS: 7.5 (High) — Network, low complexity, temporal wedge evasion
CVE-2026-33006MEDIUM08 May 2026
Apache HTTP Server: mod_auth_digest timing attack
13RISK
open
GitHub PoC
CVE-2025-58434 Proof of Concept
CVE-2025-58434CRITICAL08 May 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-5718HIGH08 May 2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISK
open
GitHub PoC
PoC and advisory for CVE-2026-44648
CVE-2026-44648HIGH08 May 2026
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
41RISK
open
GitHub PoC2
Dirty Frag (CVE-2026-43284/43500) - Linux Kernel LPE Deep Technical Analysis by Bomb
CVE-2026-43284HIGH08 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
previouspage 137 / 2,673next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.