Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
80,409 exploits
GitHub PoC
Exploit for CVE-2023-27372 with interactiev shell
CVE-2023-27372CRITICAL07 Mar 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC1
Professional PoC for CVE-2025-60787: Remote Code Execution in MotionEye (<= 0.43.1b4). This exploit demonstrates an OS Command Injection vulnerability through client-side validation bypass, allowing attackers to execute arbitrary commands via configuration files.
CVE-2025-60787HIGH07 Mar 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack07 Mar 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27372CRITICAL07 Mar 2026
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RISK
open
GitHub PoC
this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452
CVE-2023-3452CRITICAL06 Mar 2026
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
63RISK
open
GitHub PoC
Asus Router Arbitrary File Write to Remote Code Execution PoC - Fk Mirai
CVE-2024-3912CRITICAL06 Mar 2026
ASUS Router - Upload arbitrary firmware
48RISK
open
GitHub PoC
luoqichen/CVE-2025-55182-POC
CVE-2025-55182CRITICALunder attackransomware06 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
local
CVE-2023-21746HIGH06 Mar 2026
Windows NTLM Elevation of Privilege Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2019-398006 Mar 2026
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RISK
open
GitHub PoC
Full-cycle Pentest on Metasploitable (VMware/Kali). Scanned services (Apache Tomcat/8180), researched CVE-2002-0936 via Exploit-DB, and gained access using default creds (Metasploit). Performed local enumeration for SUID misconfigs, exploiting a legacy Nmap binary to escalate privileges to Root.
CVE-2002-093606 Mar 2026
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the w
28RISK
open
GitHub PoC5
MindsDB Path Traversal to RCE PoC
CVE-2026-27483HIGH06 Mar 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware06 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2014-6271
CVE-2014-6271CRITICALunder attack06 Mar 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC1
PoC of BLE cache poisoning attack
CVE-2026-51376MEDIUM05 Mar 2026
An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE
33RISK
open
GitHub PoC2
yonathanpy/CVE-2025-32462-CVE-2025-32463-PoC-Lab
CVE-2025-32462LOW05 Mar 2026
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allo
28RISK
open
VulnCheck XDB
local
CVE-2025-32463CRITICALunder attack05 Mar 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
VulnCheck XDB
local
CVE-2022-0185HIGHunder attack05 Mar 2026
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
GitHub PoC
shakyanayann/CVE-2022-0185
CVE-2022-0185HIGHunder attack05 Mar 2026
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
Metasploit300
AVideo Unauthenticated SQL Injection Credential Dump
CVE-2026-28501CRITICAL05 Mar 2026
WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
43RISK
open
Metasploit600
AVideo Encoder getImage.php Unauthenticated Command Injection
CVE-2026-29058CRITICAL05 Mar 2026
AVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.php
43RISK
open
Metasploit300
Cisco Secure Firewall Management Center Authentication Bypass RCE
CVE-2026-20079CRITICAL04 Mar 2026
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
85RISK
open
GitHub PoC
prabeershakya/CVE-2022-0185-POC
CVE-2022-0185HIGHunder attack04 Mar 2026
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RISK
open
GitHub PoC
arrhenius975/CVE-2024-38063-Exploit-Refactoring
CVE-2024-38063CRITICAL04 Mar 2026
Windows TCP/IP Remote Code Execution Vulnerability
70RISK
open
GitHub PoC1
Technical analysis and proof-of-concept for CVE-2024-1086, a Linux kernel nf_tables use-after-free vulnerability leading to local privilege escalation. Includes vulnerability breakdown, affected versions, exploitation methodology, and mitigation guidance for research and educational purposes.
CVE-2024-1086HIGHunder attackransomware04 Mar 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC
HazaVVIP/CVE-2025-30208
CVE-2025-30208MEDIUM04 Mar 2026
Vite bypasses server.fs.deny when using `?raw??`
70RISK
open
GitHub PoC2
Faridi-m/CVE-2021-22911-RocketChat
CVE-2021-2291104 Mar 2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2021-2291104 Mar 2026
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-20122MEDIUMunder attack04 Mar 2026
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack03 Mar 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
Exploit-DB
WeGIA 3.5.0 - SQL Injection
CVE-2025-62360CRITICALwebappsphp03 Mar 2026
WeGIA SQL Injection via 'id_dependente' param at endpoint `/html/funcionario/dependente_documento.php`
48RISK
open
previouspage 180 / 2,681next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.