Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
80,409 exploits
GitHub PoC
PoC exploit for CVE-2024-46987 — Camaleon CMS arbitrary path traversal (file read)
CVE-2024-46987HIGH22 Feb 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
GitHub PoC
iOxsec/CVE-2025-6018-CVE-2025-6019-Privilege-Escalation-Exploit
CVE-2025-6018HIGH22 Feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open
GitHub PoC
The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.
CVE-2025-49132CRITICAL21 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
its970/CVE-2025-68645
CVE-2025-68645HIGHunder attack21 Feb 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
VulnCheck XDB
initial-access
CVE-2025-68645HIGHunder attack21 Feb 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHunder attack21 Feb 2026
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC1
Exploitation de CVE-2022-26923
CVE-2022-26923HIGHunder attack21 Feb 2026
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL21 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-1405CRITICAL20 Feb 2026
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload
63RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware20 Feb 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC
C reimplementation of chwoot PoC
CVE-2025-32463CRITICALunder attack20 Feb 2026
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open
GitHub PoC
Path traversal vulnerability in Python's tarfile.
CVE-2025-4517CRITICAL20 Feb 2026
Arbitrary writes via tarfile realpath overflow
48RISK
open
GitHub PoC
CVE-2022-37969 poc
CVE-2022-37969HIGHunder attackransomware20 Feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub Docker environments. Includes setup instructions and commands to run the vulnerable container.
CVE-2017-5638CRITICALunder attackransomware20 Feb 2026
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISK
open
VulnCheck XDB
local
CVE-2022-37969HIGHunder attackransomware20 Feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC
A proof of concept for CVE-2025-31161, using mangled HTTP header to perform unauthenticated impersonation of any user in Crush FTP server.
CVE-2025-31161CRITICALunder attackransomware20 Feb 2026
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RISK
open
GitHub PoC
theemperorspath/CVE-2026-2441-PoC
CVE-2026-2441HIGHunder attack19 Feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISK
open
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALunder attack19 Feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-71243CRITICAL19 Feb 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISK
open
GitHub PoC1
这是基于cve-2016-4437简单的漏洞复现代码
CVE-2016-4437CRITICALunder attack19 Feb 2026
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RISK
open
VulnCheck XDB
client-side
CVE-2026-2441HIGHunder attack19 Feb 2026
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
76RISK
open
VulnCheck XDB
initial-access
CVE-2026-1281CRITICALunder attack19 Feb 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-1340CRITICALunder attack19 Feb 2026
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-47812CRITICALunder attack19 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC4
CVE-2025-71243 - SPIP Saisies Plugin RCE (Unauthenticated PHP Code Injection)
CVE-2025-71243CRITICAL19 Feb 2026
SPIP Saisies Plugin < 5.11.1 Remote Code Execution
63RISK
open
GitHub PoC
CVE-2014-6271 Exploit | by infrar3d
CVE-2014-6271CRITICALunder attack19 Feb 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
local
CVE-2022-24521HIGHunder attackransomware19 Feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC2
Unauthenticated remote code execution vulnerability in Wing FTP Server <= 7.4.3.
CVE-2025-47812CRITICALunder attack19 Feb 2026
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RISK
open
GitHub PoC
CVE-2022-24521 poc
CVE-2022-24521HIGHunder attackransomware19 Feb 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
71RISK
open
Metasploit600
MajorDoMo Supply Chain RCE via Update Poisoning
CVE-2026-27180CRITICAL18 Feb 2026
MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning
43RISK
open
previouspage 186 / 2,681next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.