Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
80,324 exploits
GitHub PoC
Analysis and PoC for CVE-2018-14847, MikroTik RouterOS Winbox information disclosure vulnerability allowing unauthenticated read access to the credential database.
CVE-2018-14847CRITICALunder attack27 Apr 2026
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC
kaleth4/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Apr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab
CVE-2026-39987CRITICALunder attack26 Apr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack26 Apr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
GitHub PoC
A black box penetration test on HackTheBox's CCTV machine achieving full root compromise via four vulnerabilities: default credentials, SQL injection (CVE-2024-51482), password hash cracking, and Remote Code Execution in motionEye (CVE-2025-60787)
CVE-2024-51482CRITICAL26 Apr 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC
A black box penetration test on HackTheBox's CCTV machine achieving full root compromise via four vulnerabilities: default credentials, SQL injection (CVE-2024-51482), password hash cracking, and Remote Code Execution in motionEye (CVE-2025-60787)
CVE-2025-60787HIGH26 Apr 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
GitHub PoC1
CVE-2026-0740
CVE-2026-0740CRITICAL25 Apr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
local
CVE-2023-32629HIGH25 Apr 2026
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack25 Apr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware25 Apr 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-3844CRITICAL25 Apr 2026
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
68RISK
open
GitHub PoC
Cybersecurity-Enthusiasts-CE/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALunder attackransomware25 Apr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
LoGGGG2402/CVE-2025-27407
CVE-2025-27407CRITICAL25 Apr 2026
Remote code execution when loading a crafted GraphQL schema
48RISK
open
GitHub PoC1
Marimo Pre-Auth RCE
CVE-2026-39987CRITICALunder attack25 Apr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
GitHub PoC
Some Proof-of-Concept (POCs) for CVE-2025-29927, CVE-2026-27978, and CVE-2026-29057 in Next.js.
CVE-2025-29927CRITICAL25 Apr 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
DONKEY0xSHOT/CVE-2017-11882-Blocker
CVE-2017-11882HIGHunder attackransomware25 Apr 2026
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
CMS Simple CVE Recode Script Python 3
CVE-2019-905325 Apr 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL25 Apr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC
CVE-2024-3273 — Authorized Penetration Test Report D-Link DNS-320L NAS | Client: Otonata
CVE-2024-3273HIGHunder attack25 Apr 2026
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
GitHub PoC1
im2sinister/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware25 Apr 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution, post-exploitation steps, and full pentesting report.
CVE-2019-9978MEDIUMunder attack25 Apr 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC
bhatbhupendra/Moniker-Link--CVE-2024-21413-
CVE-2024-21413CRITICALunder attack25 Apr 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
patch-manager
CVE-2019-1428725 Apr 2026
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC
End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack simulation.
CVE-2024-38063CRITICAL24 Apr 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE
CVE-2026-25895CRITICAL24 Apr 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RISK
open
GitHub PoC2
CVE-2025-68645
CVE-2025-68645HIGHunder attack24 Apr 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
GitHub PoC
Unauthenticated_RCE.CVE-2025-47812
CVE-2025-47812CRITICALunder attack24 Apr 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC1
its simple Shellshock exploit
CVE-2014-6271CRITICALunder attack24 Apr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Bug Bounty: CVE-2023-50839 IDOR identified in a third-party support component via 'gau' and 'Nuclei'. Despite perimeter redirects, the outdated software remained exposed. Confirmed through manual header analysis. Severity: 5.3 (Medium). Focused on Defense in Depth failures and PII protection. Status: Reported on Intigriti.
CVE-2023-50839CRITICAL24 Apr 2026
WordPress JS Help Desk – Best Help Desk & Support Plugin <= 2.8.1 is vulnerable to SQL Injection
63RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack24 Apr 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
previouspage 155 / 2,678next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.