Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,953cataloged exploits
36,205CVEs with public exploitation
24,695lab-tested
8,829 exploits
VulnCheck XDB
client-side
CVE-2021-22204MEDIUMunder attack13 Jun 2026
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHunder attack13 Jun 2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALunder attack13 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-50751CRITICALunder attackransomware12 Jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-53435HIGH12 Jun 2026
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrar
53RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware12 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALunder attack11 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
VulnCheck XDB
local
CVE-2023-21768HIGH11 Jun 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL11 Jun 2026
TP-LINK Tapo C200 remote code execution vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL11 Jun 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-10795HIGH11 Jun 2026
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL11 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
VulnCheck XDB
local
CVE-2023-0386HIGHunder attack11 Jun 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALunder attack11 Jun 2026
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23550CRITICAL11 Jun 2026
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
68RISK
open
VulnCheck XDB
info-leak
CVE-2025-43529HIGHunder attack11 Jun 2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL11 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-0257HIGHunder attackransomware10 Jun 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open
VulnCheck XDB
local
CVE-2023-2640HIGH10 Jun 2026
On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlay
61RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-28318HIGHunder attack10 Jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2026-5027HIGH10 Jun 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-24813CRITICALunder attack10 Jun 2026
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
VulnCheck XDB
local
CVE-2023-32629HIGH10 Jun 2026
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
61RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL10 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-50751CRITICALunder attackransomware10 Jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware10 Jun 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3721MEDIUM10 Jun 2026
TBK DVR-4104/DVR-4216 os command injection
55RISK
open
VulnCheck XDB
initial-access
CVE-2025-29927CRITICAL10 Jun 2026
Authorization Bypass in Next.js Middleware
85RISK
open
VulnCheck XDB
initial-access
CVE-2026-24423CRITICALunder attackransomware10 Jun 2026
SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-45247CRITICALunder attack09 Jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.