Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
80,409 exploits
VulnCheck XDB
initial-access
CVE-2026-3395MEDIUM02 Mar 2026
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
48RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware01 Mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
D3b0j33t/CVE-2026-2441-PoC
CVE-2026-2441HIGHunder attack01 Mar 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISK
open
GitHub PoC
CVE-2014-0160
CVE-2014-0160HIGHunder attack01 Mar 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
This repository provides production-ready detection engineering content for **CVE-2025-25257**, a pre-authentication SQL Injection vulnerability in Fortinet FortiWeb Fabric Connector versions 7.0 through 7.6.x. Successful exploitation can lead to Remote Code Execution without any prior authentication.
CVE-2025-25257CRITICALunder attack01 Mar 2026
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-3395MEDIUM01 Mar 2026
MaxSite CMS MarkItUp Preview AJAX Endpoint preview-ajax.php eval code injection
48RISK
open
Metasploit600
FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass
CVE-2026-27636HIGH01 Mar 2026
FreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache
36RISK
open
Metasploit600
FreeScout Unauthenticated RCE via ZWSP .htaccess Bypass
CVE-2026-28289CRITICAL01 Mar 2026
FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Code Execution
55RISK
open
GitHub PoC
Black box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847
CVE-2022-0847HIGHunder attack01 Mar 2026
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-2441HIGHunder attack01 Mar 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISK
open
GitHub PoC
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
CVE-2021-4034HIGHunder attackransomware01 Mar 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
7rootsec/CVE-2022-21661-Technical-Analysis
CVE-2022-21661HIGH01 Mar 2026
SQL injection in WordPress
78RISK
open
GitHub PoC
Time-Based Blind SQL Injection Exploit for the OpenSIPs Control Panel (or my first CVE!)
CVE-2026-36670HIGH01 Mar 2026
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) pr
41RISK
open
GitHub PoC1
Laravel-RCE: CVE-2017-9841
CVE-2017-9841CRITICALunder attack01 Mar 2026
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC
CVE-2022-22965
CVE-2022-22965CRITICALunder attack01 Mar 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
GitHub PoC1
Authenticated remote code execution in Pluck CMS before 4.7.13.
CVE-2020-2960728 Feb 2026
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RISK
open
Metasploit600
openDCIM install.php SQL Injection to RCE
CVE-2026-28517CRITICAL28 Feb 2026
openDCIM <= 23.04 OS Command Injection via dot Configuration Parameter
63RISK
open
GitHub PoC
bcarrulo/Lab-CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware28 Feb 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
Metasploit600
openDCIM install.php SQL Injection to RCE
CVE-2026-28515CRITICAL28 Feb 2026
openDCIM <= 23.04 Missing Authorization in install.php
63RISK
open
Metasploit600
openDCIM install.php SQL Injection to RCE
CVE-2026-28516CRITICAL28 Feb 2026
openDCIM <= 23.04 SQL Injection in Config::UpdateParameter
43RISK
open
VulnCheck XDB
initial-access
CVE-2026-21902CRITICAL28 Feb 2026
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
53RISK
open
GitHub PoC
Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.
CVE-2011-252328 Feb 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
VulnCheck XDB
local
CVE-2024-21626HIGH28 Feb 2026
runc container breakout through process.cwd trickery and leaked fds
61RISK
open
GitHub PoC
CVE-2017-9805 S2-052 PoC
CVE-2017-9805HIGHunder attack28 Feb 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware28 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-9805HIGHunder attack28 Feb 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
GitHub PoC3
Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.
CVE-2025-55182CRITICALunder attackransomware28 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Public advisory and technical analysis for CVE-2026-36590, a NanoMQ v0.24.9 denial-of-service vulnerability.
CVE-2026-36590HIGH28 Feb 2026
An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in
41RISK
open
GitHub PoC
Metasploit exploit for the CVE-2025-50286.
CVE-2025-50286HIGH28 Feb 2026
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
56RISK
open
GitHub PoC
updated script
CVE-2019-905328 Feb 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
previouspage 182 / 2,681next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.