Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
8,829 exploits
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware22 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware21 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
info-leak
CVE-2023-23752MEDIUMunder attack21 Jun 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL21 Jun 2026
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
info-leak
CVE-2025-24071MEDIUM21 Jun 2026
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
VulnCheck XDB
initial-access
CVE-2026-21858CRITICAL21 Jun 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-49777CRITICAL21 Jun 2026
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISK
open
VulnCheck XDB
info-leak
CVE-2026-32202MEDIUMunder attack21 Jun 2026
Windows Shell Spoofing Vulnerability
75RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-68613CRITICALunder attack21 Jun 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack21 Jun 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack21 Jun 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
info-leak
CVE-2023-23752MEDIUMunder attack21 Jun 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL20 Jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
VulnCheck XDB
local
CVE-2021-3560HIGHunder attack19 Jun 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
VulnCheck XDB
info-leak
CVE-2026-7515CRITICAL19 Jun 2026
BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
48RISK
open
VulnCheck XDB
initial-access
CVE-2022-0543CRITICALunder attack19 Jun 2026
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL19 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-42208CRITICALunder attack18 Jun 2026
LiteLLM: SQL injection in Proxy API key verification
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-27876HIGHunder attackransomware18 Jun 2026
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open
VulnCheck XDB
info-leak
CVE-2026-7515CRITICAL18 Jun 2026
BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-39808CRITICALunder attack18 Jun 2026
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-57819CRITICALunder attack18 Jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL18 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
VulnCheck XDB
local
CVE-2025-21479HIGHunder attack18 Jun 2026
Incorrect Authorization in Graphics
71RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-54123CRITICAL18 Jun 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open
VulnCheck XDB
initial-access
CVE-2021-3442717 Jun 2026
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessibl
50RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-7465HIGH17 Jun 2026
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-8206CRITICAL17 Jun 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-49060CRITICAL17 Jun 2026
WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALunder attack17 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.