Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,324cataloged exploits
37,130CVEs with public exploitation
24,695lab-tested
80,324 exploits
Exploit-DB
Throttlestop Kernel Driver - Kernel Out-of-Bounds Write Privilege Escalation
CVE-2025-7771HIGHlocalwindows22 Apr 2026
Code Execution / Escalation of Privileges in ThrottleStop
41RISK
open
GitHub PoC1
Analysis and exploit for CVE-2026-25250, a Secure Boot bypass in Horizon DataSys Reboot Restore where shdloader.efi loads Shield.efi without verification.
CVE-2026-25250MEDIUM22 Apr 2026
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot
33RISK
open
Exploit-DB
WordPress Plugin 5.2.0 - Broken Access Control
CVE-2025-67586MEDIUMwebappsmultiple22 Apr 2026
WordPress Highlight and Share plugin <= 5.2.0 - Broken Access Control vulnerability
33RISK
open
GitHub PoC
CVE-2019-15107 Webmin RCE (unauthenticated) exploit
CVE-2019-15107CRITICALunder attackransomware22 Apr 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC4
Full exploit for the Android vulnerability Bad Binder found in early Google Pixel phones.
CVE-2019-2215HIGHunder attack22 Apr 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC
Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware22 Apr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack22 Apr 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALunder attackransomware22 Apr 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVE-2026-34415CRITICAL22 Apr 2026
Xerte Online Toolkits File Upload RCE via elfinder Connector
63RISK
open
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVE-2026-34413HIGH22 Apr 2026
Xerte Online Toolkits Missing Authentication via connector.php
56RISK
open
GitHub PoC1
End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock (CVE-2014-6271).
CVE-2014-6271CRITICALunder attack22 Apr 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVE-2026-34414HIGH22 Apr 2026
Xerte Online Toolkits Path Traversal via connector.php
56RISK
open
GitHub PoC
CVEs-Labs/CVE-2026-21876
CVE-2026-21876CRITICAL22 Apr 2026
OWASP CRS has multipart bypass using multiple content-type parts
53RISK
open
Metasploit600
Xerte Online Toolkits Arbitrary File Upload - Unauthenticated Media Upload
CVE-2026-41459MEDIUM22 Apr 2026
Xerte Online Toolkits Path Disclosure via /setup
48RISK
open
VulnCheck XDB
info-leak
CVE-2022-3590MEDIUM22 Apr 2026
WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
48RISK
open
GitHub PoC
jpselva/CVE-2023-4863
CVE-2023-4863HIGHunder attack22 Apr 2026
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to
93RISK
open
GitHub PoC1
(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)
CVE-2026-29053HIGH21 Apr 2026
Ghost Vulnerable to Remote Code Execution via Malicious Themes
56RISK
open
GitHub PoC
ClaraSto/CVE-2024-1086_Ausarbeitung
CVE-2024-1086HIGHunder attackransomware21 Apr 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC
Qualitative TVRA for a multi-VLAN enterprise lab: Stored XSS on WebGoat (HIGH, 16), Stored XSS on Magento (ABSENT, MEDIUM, 8), and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25). Scored via Likelihood × Impact using CVSS v3.0 and ZAP/Nessus/Wireshark evidence.
CVE-2017-0144HIGHunder attackransomware20 Apr 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit300
BerriAI LiteLLM Proxy Pre-Auth SQL Injection Scanner
CVE-2026-42208CRITICALunder attack20 Apr 2026
LiteLLM: SQL injection in Proxy API key verification
100RISK
open
GitHub PoC1
The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or verification. This enables any attacker to generate a reset token for arbitrary users and directly reset their password, leading to a complete account takeover (ATO).
CVE-2025-58434CRITICAL20 Apr 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISK
open
GitHub PoC
Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)
CVE-2026-3462MEDIUM20 Apr 2026
Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
33RISK
open
GitHub PoC
We hope to reproduce CVE-2021-41773 to deepen our understanding of real-world cybersecurity vulnerabilities so that we can be knowledgeable about exploits in industry and academic work.
CVE-2021-41773HIGHunder attackransomware20 Apr 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack20 Apr 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
Multi-VLAN virtual network across 10 VMs: GRE tunneling, nftables firewall, Active Directory, BIND9 DNS, Kea DHCP, Docker web services, SMB file sharing. Vulnerability assessment using OWASP ZAP (Stored XSS) and Nessus (CVE-2017-0144 EternalBlue). Validated with Wireshark.
CVE-2017-0144HIGHunder attackransomware20 Apr 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC1
wa6n3r/CVE-2024-3400
CVE-2024-3400CRITICALunder attackransomware20 Apr 2026
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-35616CRITICALunder attack20 Apr 2026
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RISK
open
GitHub PoC83
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
CVE-2016-3088CRITICALunder attack20 Apr 2026
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3400CRITICALunder attackransomware20 Apr 2026
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
Type Local Privilege Escalation exploit for CVE-2021-3493(Ubuntu Kernel vulnerability) documrnted during TryHackme Lab
CVE-2021-3493HIGHunder attack20 Apr 2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open
previouspage 157 / 2,678next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.