Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
80,409 exploits
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware11 Feb 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
bixiPRO/Drupalgeddon2-CVE-2018-7600
CVE-2018-7600CRITICALunder attackransomware10 Feb 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
bananoname/CVE-2024-6386-WPML-SSTI
CVE-2024-6386CRITICAL10 Feb 2026
WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
53RISK
open
GitHub PoC2
SumatraPDF versions 3.5.0 to 3.5.2 disable TLS hostname verification during update checks # (using INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and do not perform any signature or integrity # validation on the downloaded installer.
CVE-2026-25961HIGH10 Feb 2026
SumatraPDF Update MITM -> Arbitrary Code Execution
41RISK
open
GitHub PoC3
George0Papasotiriou/CVE-2025-14174-Chrome-Zero-Day
CVE-2025-14174HIGHunder attack10 Feb 2026
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
76RISK
open
GitHub PoC1
George0Papasotiriou/CVE-2025-61882-Oracle-BI-Publisher-RCE
CVE-2025-61882CRITICALunder attackransomware10 Feb 2026
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integratio
100RISK
open
GitHub PoC1
George0Papasotiriou/CVE-2025-59470-PostgreSQL-Command-Injection
CVE-2025-59470CRITICAL10 Feb 2026
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal
48RISK
open
GitHub PoC
faysalferdous/CVE-2025-68645-Exploiting-Zimbra-Webmail-LFI-Vulnerability
CVE-2025-68645HIGHunder attack10 Feb 2026
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
98RISK
open
GitHub PoC
Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).
CVE-2024-21413CRITICALunder attack10 Feb 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL10 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC3
CVE-2025-54253 | CVE-2025-54254 | Adobe Experience Manager Forms XXE → RCE Framework
CVE-2025-54253CRITICALunder attack10 Feb 2026
Adobe Experience Manager | Incorrect Authorization (CWE-863)
100RISK
open
GitHub PoC
RCE on Next 16.0.6
CVE-2025-55182CRITICALunder attackransomware10 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
George0Papasotiriou/CVE-2025-55182-React2Shell-CVSS-10.0-
CVE-2025-55182CRITICALunder attackransomware10 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH10 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-6019HIGH10 Feb 2026
Libblockdev: lpe from allow_active to root in libblockdev via udisks
41RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-54254HIGH10 Feb 2026
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
63RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-1357CRITICAL10 Feb 2026
Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC1
George0Papasotiriou/CVE-2025-15556-Notepad-WinGUp-Updater-RCE
CVE-2025-15556HIGHunder attack10 Feb 2026
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
71RISK
open
VulnCheck XDB
initial-access
CVE-2025-49132CRITICAL10 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC1
Enumeration tool for CVE-2024-45440
CVE-2024-45440MEDIUM10 Feb 2026
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash
48RISK
open
GitHub PoC1
CVE-2025-49132: Pterodactyl Panel UnauthN LFI to RCE (w/ pearcmd) in posix sh
CVE-2025-49132CRITICAL10 Feb 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-25939CRITICAL10 Feb 2026
FUXA Unauthenticated Remote Arbitrary Scheduler Write
53RISK
open
VulnCheck XDB
denial-of-service
CVE-2023-44487HIGHunder attack10 Feb 2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-3408510 Feb 2026
20RISK
open
VulnCheck XDB
client-side
CVE-2018-7600CRITICALunder attackransomware10 Feb 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware10 Feb 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC4
Auto exploit for CVE-2025-6018 & CVE-2025-6019 based on https://github.com/0rionCollector/Exploit-Chain-CVE-2025-6018-6019
CVE-2025-6018HIGH10 Feb 2026
Pam-config: lpe from unprivileged to allow_active in pam
41RISK
open
GitHub PoC1
George0Papasotiriou/CVE-2025-8110-Gogs-Remote-Code-Execution
CVE-2025-8110HIGHunder attack10 Feb 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-36847CRITICAL10 Feb 2026
Simple File List < 4.2.3 - Remote Code Execution
75RISK
open
GitHub PoC
HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.
CVE-2017-7921CRITICALunder attack09 Feb 2026
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open
previouspage 191 / 2,681next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.