Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
80,409 exploits
GitHub PoC1
ApacheHunter detects CVE-2024-22393 in Apache Answer servers. Like Wappalyzer but CLI-based. Scans headers, page content, meta tags, and paths to identify Apache versions and vulnerable installations (≤1.2.1). No output files—just real-time results.
CVE-2024-22393CRITICAL09 Mar 2026
Apache Answer: Pixel Flood Attack by uploading the large pixel file
48RISK
open
GitHub PoC
CVE-2025-49844
CVE-2025-49844CRITICAL09 Mar 2026
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-20127CRITICALunder attack09 Mar 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
GitHub PoC1
PoC for CVE-2024-22393: Pixel Flood DoS in Apache Answer ≤1.2.1. Upload crafted 5KB image with fake 64Kx64K dimensions. Server allocates memory for 4B+ pixels and crashes. Find targets via "Powered by Apache Answer." Check bounty program rules before testing—DoS testing is often prohibited.
CVE-2024-22393CRITICAL09 Mar 2026
Apache Answer: Pixel Flood Attack by uploading the large pixel file
48RISK
open
GitHub PoC
demo application showing off SQL Injection exploit in django 5.2.7
CVE-2025-64459CRITICAL09 Mar 2026
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RISK
open
GitHub PoC1
SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.
CVE-2024-49138HIGHunder attack09 Mar 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC3
cupntlm
CVE-2025-33073HIGHunder attack09 Mar 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
client-side
CVE-2026-25253HIGH09 Mar 2026
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
46RISK
open
GitHub PoC
VX Search Enterprise v10.1.12 Remote Buffer Overflow
CVE-2017-1522009 Mar 2026
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginni
23RISK
open
GitHub PoC10
PoC for CVE-2025-60787 - Authenticated RCE in motionEye for all versions up to 0.43.1b4 (included)
CVE-2025-60787HIGH08 Mar 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
GitHub PoC
0axz-tools/CVE-2025-6440
CVE-2025-6440CRITICAL08 Mar 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack08 Mar 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC3
CVE-2023-38831 is a Zero-day WinRAR vulnerability that lets attackers disguise malicious files in archives, tricking users into executing harmful content.
CVE-2023-38831HIGHunder attackransomware08 Mar 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack08 Mar 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Dockerized vulnerable lab demonstrating CVE-2024-2083 in ZenML, a path traversal vulnerability in the step logs API allowing arbitrary file read.
CVE-2024-2083CRITICAL08 Mar 2026
Directory Traversal in zenml-io/zenml
60RISK
open
GitHub PoC
A demo and explanation of CVE-2026-31431
CVE-2026-31431HIGHunder attack08 Mar 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Yetazyyy/CVE-2026-0770
CVE-2026-0770CRITICALunder attack08 Mar 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISK
open
GitHub PoC824
CVE-2026-24061 exploit PoC
CVE-2026-24061CRITICALunder attack08 Mar 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC
Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking, and defensive countermeasures
CVE-2024-21413CRITICALunder attack08 Mar 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
gustavorobertux/cisco-cve-2023-20198-checker
CVE-2023-20198CRITICALunder attack08 Mar 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open
GitHub PoC8
ZenoMinder Blind SQL Injection PoC
CVE-2024-51482CRITICAL08 Mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC2
lil0xplorer/CVE-2025-60787_PoC
CVE-2025-60787HIGH08 Mar 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
GitHub PoC
An automated, high-precision zero-shot evaluation pipeline for OpenAI's CLIP model on CIFAR-10. Features 88.80% accuracy, Safetensors security mitigation (CVE-2025-32434), and AI Native (Trae) workflow.
CVE-2025-32434CRITICAL08 Mar 2026
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
48RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL08 Mar 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC
ZoneMinder Time-Based SQL Injection (CVE-2024-51482) Exploit POC
CVE-2024-51482CRITICAL08 Mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-20122MEDIUMunder attack07 Mar 2026
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL07 Mar 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALunder attack07 Mar 2026
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RISK
open
GitHub PoC14
Authenticated time-based blind SQL injection PoC for ZoneMinder CVE-2024-51482 (v1.37.* <= 1.37.64)
CVE-2024-51482CRITICAL07 Mar 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC
Exploit for CVE-2023-27372 with interactiev shell
CVE-2023-27372CRITICAL07 Mar 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
previouspage 179 / 2,681next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.