Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
8,829 exploits
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack10 Jul 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALunder attackransomware10 Jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware10 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL10 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
client-side
CVE-2024-47176MEDIUM10 Jul 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
local
CVE-2026-46331HIGH10 Jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack10 Jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-49049HIGH10 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware09 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware09 Jul 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware09 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-1571509 Jul 2026
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a ma
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-8037CRITICALunder attack09 Jul 2026
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-48908CRITICAL09 Jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack09 Jul 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-56290CRITICAL08 Jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-44825HIGH08 Jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISK
open
VulnCheck XDB
initial-access
CVE-2022-24706CRITICALunder attack08 Jul 2026
Remote Code Execution Vulnerability in Packaging
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware08 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALunder attackransomware08 Jul 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack08 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack07 Jul 2026
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL07 Jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-42271HIGHunder attack07 Jul 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware07 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack07 Jul 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-48282CRITICAL07 Jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack07 Jul 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-48611CRITICAL07 Jul 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-0920CRITICAL06 Jul 2026
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.