Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
80,324 exploits
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack01 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack01 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack01 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack01 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack01 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
对 CVE-2026-31431 的复现分析、C 改编的 exp。
CVE-2026-31431HIGHunder attack01 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack01 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack30 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
Exploit-DB
Windows 11 25H2 - Heap Overflow
CVE-2026-21244HIGHlocalwindows30 Apr 2026
Windows Hyper-V Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack30 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
Exploit-DB
Windows 11 25H2 - Heap Overflow
CVE-2026-21248HIGHlocalwindows30 Apr 2026
Windows Hyper-V Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack30 Apr 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Exploit-DB
SUSE Manager 4.3.15 - Code Execution
CVE-2025-46811CRITICALwebappsmultiple30 Apr 2026
SUSE Multi Linux Manager allows code execution via unprotected websocket endpoint
53RISK
open
Exploit-DB
SumatraPDF 3.5.2 - Remote Code Execution
CVE-2026-25961HIGHwebappsmultiple30 Apr 2026
SumatraPDF Update MITM -> Arbitrary Code Execution
41RISK
open
Exploit-DB
Camaleon CMS v2.9.0 - Path Traversal
CVE-2024-46987HIGHwebappsmultiple30 Apr 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
GitHub PoC
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
CVE-2026-7537HIGH30 Apr 2026
MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC31
BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide
CVE-2026-31431HIGHunder attack30 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack30 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
HackTheBox — CCTV (Easy/Linux) | CVE-2024-51482 + SqlMap+ SSH Key + Root
CVE-2024-51482CRITICAL30 Apr 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack30 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-3844CRITICAL30 Apr 2026
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
68RISK
open
Exploit-DB
Windows 11 23H2 - Denial of Service (DoS)
CVE-2025-47987HIGHlocalwindows30 Apr 2026
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
Penetration test report for MegaQuagga Publishing documenting a six-phase engagement that chained CVE-2019-9978 and CVE-2023-4842 to achieve unauthenticated Remote Code Execution and a persistent Meterpreter session. Includes full methodology, exploitation evidence, and prioritized remediation recommendations.
CVE-2019-9978MEDIUMunder attack30 Apr 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC2
0xabdoulaye/CPANEL-CVE-2026-41940
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Exploit-DB
Js2Py 0.74 - RCE
CVE-2024-28397MEDIUMwebappsmultiple30 Apr 2026
An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a
48RISK
open
GitHub PoC5
shahidmallaofficial/cpanel-cve-2026-41940-fix
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
previouspage 149 / 2,678next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.