Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
80,324 exploits
VulnCheck XDB
initial-access
CVE-2025-55177MEDIUMunder attack24 Apr 2026
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Bu
63RISK
open
GitHub PoC
Poc for React2Shell CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware24 Apr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC2
CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.
CVE-2025-55177MEDIUMunder attack24 Apr 2026
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Bu
63RISK
open
GitHub PoC
End-to-end SOC investigation: CVE-2011-2523 kill chain, multi-source log correlation, incident report — MITRE ATT&CK T1190
CVE-2011-252324 Apr 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack simulation.
CVE-2024-38063CRITICAL24 Apr 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC2
CVE-2025-68645
CVE-2025-68645HIGHunder attack24 Apr 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
VulnCheck XDB
initial-access
CVE-2026-25895CRITICAL24 Apr 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RISK
open
GitHub PoC
AbokorMAHAMMADMOUSSE/CVE-2025-25279-Mattermost-Path-Traversal
CVE-2025-25279CRITICAL24 Apr 2026
Arbitrary file read in Mattermost Boards via import & export board archive
53RISK
open
GitHub PoC
Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation
CVE-2025-29927CRITICAL24 Apr 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Unauthenticated_RCE.CVE-2025-47812
CVE-2025-47812CRITICALunder attack24 Apr 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE
CVE-2026-25895CRITICAL24 Apr 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RISK
open
GitHub PoC1
its simple Shellshock exploit
CVE-2014-6271CRITICALunder attack24 Apr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Bug Bounty: CVE-2023-50839 IDOR identified in a third-party support component via 'gau' and 'Nuclei'. Despite perimeter redirects, the outdated software remained exposed. Confirmed through manual header analysis. Severity: 5.3 (Medium). Focused on Defense in Depth failures and PII protection. Status: Reported on Intigriti.
CVE-2023-50839CRITICAL24 Apr 2026
WordPress JS Help Desk – Best Help Desk & Support Plugin <= 2.8.1 is vulnerable to SQL Injection
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-21962CRITICALunder attack24 Apr 2026
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo
90RISK
open
GitHub PoC1
Recreation and analysis of a curious logic error in Apache 2.4.49 that escalated to remote code execution
CVE-2021-41773HIGHunder attackransomware23 Apr 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-39813CRITICAL23 Apr 2026
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
53RISK
open
GitHub PoC
Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving SYSTEM-level access via Meterpreter. Includes full attack chain, post exploitation, and mitigation via MS17-010 patching, tested in an isolated ethical lab environment.
CVE-2017-0144HIGHunder attackransomware23 Apr 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386
CVE-2023-0386HIGHunder attack23 Apr 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC
Find jenkins environment and checks for CVE-2024-23897
CVE-2024-23897CRITICALunder attackransomware23 Apr 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
CVE-2024-3094
CVE-2024-3094CRITICAL23 Apr 2026
Xz: malicious code in distributed source
70RISK
open
VulnCheck XDB
initial-access
CVE-2017-0144HIGHunder attackransomware23 Apr 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
VulnCheck XDB
info-leak
CVE-2022-1026HIGH22 Apr 2026
Kyocera Net View Address Book Exposure
61RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware22 Apr 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC4
Full exploit for the Android vulnerability Bad Binder found in early Google Pixel phones.
CVE-2019-2215HIGHunder attack22 Apr 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC
CVE-2019-15107 Webmin RCE (unauthenticated) exploit
CVE-2019-15107CRITICALunder attackransomware22 Apr 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC1
Analysis and exploit for CVE-2026-25250, a Secure Boot bypass in Horizon DataSys Reboot Restore where shdloader.efi loads Shield.efi without verification.
CVE-2026-25250MEDIUM22 Apr 2026
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot
33RISK
open
Exploit-DB
WordPress Plugin 5.2.0 - Broken Access Control
CVE-2025-67586MEDIUMwebappsmultiple22 Apr 2026
WordPress Highlight and Share plugin <= 5.2.0 - Broken Access Control vulnerability
33RISK
open
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVE-2026-34415CRITICAL22 Apr 2026
Xerte Online Toolkits File Upload RCE via elfinder Connector
63RISK
open
Metasploit600
Flowise CSV Agent Prompt Injection RCE
CVE-2026-41264CRITICAL22 Apr 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
43RISK
open
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVE-2026-34414HIGH22 Apr 2026
Xerte Online Toolkits Path Traversal via connector.php
56RISK
open
previouspage 156 / 2,678next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.