Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
80,324 exploits
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack30 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
Exploit-DB
Erugo 0.2.14 - Remote Code Execution (RCE)
CVE-2026-24897CRITICALwebappsmultiple30 Apr 2026
Authenticated Remote Code Execution via Arbitrary File Upload
48RISK
open
GitHub PoC5
shahidmallaofficial/cpanel-cve-2026-41940-fix
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Exploit-DB
Windows 11 25H2 - Heap Overflow
CVE-2026-21248HIGHlocalwindows30 Apr 2026
Windows Hyper-V Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
Remediation report for MegaQuagga Publishing validating the mitigation of CVE-2019-9978 through progressive defensive layering. Documents reverse proxy insertion, ModSecurity WAF deployment, Graylog SIEM integration, and SSL/TLS enforcement using multi-stage Wireshark PCAP analysis across pfSense WAN and LAN interfaces.
CVE-2019-9978MEDIUMunder attack30 Apr 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
Exploit-DB
BusyBox 1.37.0 - Path Traversal
CVE-2026-26157HIGHwebappsmultiple30 Apr 2026
Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitization
41RISK
open
Exploit-DB
Windows 11 25H2 - Heap Overflow
CVE-2026-21244HIGHlocalwindows30 Apr 2026
Windows Hyper-V Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
My first hands-on Intel 471 threat hunting workshop experience investigating CVE-2023-46604 using Elastic SIEM, vulnerability intelligence, and post-exploitation detection.
CVE-2023-46604CRITICALunder attackransomware30 Apr 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation.
CVE-2014-6271CRITICALunder attack30 Apr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Penetration test report for MegaQuagga Publishing documenting a six-phase engagement that chained CVE-2019-9978 and CVE-2023-4842 to achieve unauthenticated Remote Code Execution and a persistent Meterpreter session. Includes full methodology, exploitation evidence, and prioritized remediation recommendations.
CVE-2019-9978MEDIUMunder attack30 Apr 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware30 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Exploit-DB
Craft CMS 5.6.16 - RCE
CVE-2025-32432CRITICALunder attackwebappsmultiple29 Apr 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC
dinhthihanhle1989-max/CVE-2024-29988
CVE-2024-29988HIGHunder attack29 Apr 2026
SmartScreen Prompt Security Feature Bypass Vulnerability
83RISK
open
GitHub PoC7
Post-Exploitation Session Validation Tool for CVE-2026-41940
CVE-2026-41940CRITICALunder attackransomware29 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC3
Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass).
CVE-2026-42167HIGH29 Apr 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISK
open
GitHub PoC26
CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani
CVE-2026-41940CRITICALunder attackransomware29 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Exploit-DB
FacturaScripts 2025.43 - XSS
CVE-2025-69210LOWwebappsmultiple29 Apr 2026
FacturaScripts vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
28RISK
open
GitHub PoC1
Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)
CVE-2024-4577CRITICALunder attackransomware29 Apr 2026
Argument Injection in PHP-CGI
100RISK
open
Metasploit600
Apache ActiveMQ RCE via Jolokia addNetworkConnector
CVE-2026-34197HIGHunder attack29 Apr 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISK
open
GitHub PoC
Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.
CVE-2024-8503CRITICAL29 Apr 2026
VICIdial Unauthenticated SQL Injection
85RISK
open
Metasploit600
Copy Fail AF_ALG + authencesn Page-Cache Write
CVE-2026-31431HIGHunder attack29 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Wise-Security/CVE-2026-38945
CVE-2026-38945HIGH29 Apr 2026
Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary cod
41RISK
open
VulnCheck XDB
info-leak
CVE-2024-8503CRITICAL29 Apr 2026
VICIdial Unauthenticated SQL Injection
85RISK
open
Exploit-DB
Xibo CMS 4.3.0 - RCE via SSTI
CVE-2025-62639webappsmultiple29 Apr 2026
20RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack29 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
Exploit-DB
phpMyFAQ 4.0.16 - Improper Authorization
CVE-2026-24421MEDIUMwebappsphp29 Apr 2026
phpMyFAQ missing authorization exposes /api/setup/backup to any authenticated user
33RISK
open
Exploit-DB
GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)
CVE-2026-22241HIGHwebappsmultiple29 Apr 2026
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
41RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack29 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
previouspage 153 / 2,678next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.