Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
80,409 exploits
VulnCheck XDB
local
CVE-2025-6019HIGH14 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
GitHub PoC12
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
CVE-2026-28992MEDIUM14 Feb 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RISK
open
GitHub PoC12
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
CVE-2026-28992MEDIUM14 Feb 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RISK
open
GitHub PoC5
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.
CVE-2025-70830CRITICAL14 Feb 2026
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut
48RISK
open
GitHub PoC50
The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver
CVE-2026-0828HIGH14 Feb 2026
Kernel driver vulnerability in Safetica Endpoint Client
41RISK
open
GitHub PoC
Домашняя работа по Pyton № 10 CVE-2020-11022 Краткое описание CVE-2020-11022 — уязвимость типа Reflected XSS (межсайтовый скриптинг), связанная с некорректной обработкой пользовательского ввода, который отражается в HTML-ответе без экранирования. Атакующий может внедрить JavaScript-код, который выполнится в браузере пользователя.
CVE-2020-11022MEDIUM14 Feb 2026
jQuery has a potential XSS vulnerability
55RISK
open
GitHub PoC
A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.
CVE-2026-24061CRITICALunder attack14 Feb 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC
Samba 3.0.20 CVE-2007-2447 Exploit
CVE-2007-244714 Feb 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
mbanyamer/CVE-2026-26335-Calero-VeraSMART-RCE
CVE-2026-26335CRITICAL14 Feb 2026
Calero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE
48RISK
open
GitHub PoC1
CVE-2024-34102 exploit for python3
CVE-2024-34102CRITICALunder attack13 Feb 2026
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
GitHub PoC
BIG02-bot/React2Shell-CVE-2025-55182-An-lise-T-cnica
CVE-2025-55182CRITICALunder attackransomware13 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC4
watchtowrlabs/watchTowr-vs-SolarWinds-WebHelpDesk-CVE-2025-40552-CVE-2025-40553
CVE-2025-40552CRITICAL13 Feb 2026
SolarWinds Web Help Desk Authentication Bypass Vulnerability
75RISK
open
GitHub PoC1
针对 Next.js 原型污染漏洞 (CVE-2025-55182) 的高效批量检测工具。
CVE-2025-55182CRITICALunder attackransomware13 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-34102CRITICALunder attack13 Feb 2026
XXE can expose crypt key and other secrets granting full admin access
100RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH13 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
GitHub PoC1
Vulnerability chaining leads to privilege escalation
CVE-2025-6018HIGH13 Feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH13 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware13 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-1357CRITICAL13 Feb 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
local
CVE-2025-6019HIGH12 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware12 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Sn0wBaall/CVE-2023-4220-PoC
CVE-2023-4220HIGH12 Feb 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
GitHub PoC2
React2Shell (CVE-2025-55182) POC
CVE-2025-55182CRITICALunder attackransomware12 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC5
CVE-2025-6018 CVE-2025-6019 PoC Exploit - Local Privilege Escalation in openSUSE/SUSE Linux Enterprise 15 - PAM bypass + udisks2 XFS race condition LPE to root
CVE-2025-6018HIGH12 Feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open
GitHub PoC
mbanyamer/CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown
CVE-2026-26235HIGH12 Feb 2026
JUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing Authentication
41RISK
open
GitHub PoC
Real-world information security risk assessment based on the Oracle E-Business Suite zero-day (CVE-2025-61882). Analyses attacker methods, enterprise risks, and mitigation strategies using ISO 27001, NIST CSF, Cyber Essentials and COBIT.
CVE-2025-61882CRITICALunder attackransomware12 Feb 2026
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
GitHub PoC3
CVE-2025-49132_PHP_PEAR_METHOD
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC1
Exploit CVE-2025-49132 Pterodactyl Panel RCE
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL12 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
previouspage 189 / 2,681next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.