Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
8,829 exploits
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL31 May 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
info-leak
CVE-2024-38475CRITICALunder attack31 May 2026
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
100RISK
open
VulnCheck XDB
local
CVE-2024-1086HIGHunder attackransomware31 May 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware31 May 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
local
CVE-2025-38352HIGHunder attack30 May 2026
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-42208CRITICALunder attack30 May 2026
LiteLLM: SQL injection in Proxy API key verification
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 May 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-5947CRITICAL30 May 2026
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-36401CRITICALunder attack30 May 2026
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
100RISK
open
VulnCheck XDB
local
CVE-2026-43494HIGH30 May 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALunder attackransomware30 May 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 May 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-8732CRITICAL30 May 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-42589CRITICAL30 May 2026
Gotenberg: Unauthenticated RCE via ExifTool Metadata Key Injection
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-21413CRITICALunder attack30 May 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-24893CRITICALunder attack29 May 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-1263529 May 2026
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open
VulnCheck XDB
initial-access
CVE-2024-47176MEDIUM29 May 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-0257HIGHunder attackransomware29 May 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2022-26923HIGHunder attack29 May 2026
Active Directory Domain Services Elevation of Privilege Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-31431HIGHunder attack28 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-2093328 May 2026
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.
50RISK
open
VulnCheck XDB
local
CVE-2026-43494HIGH28 May 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL28 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
VulnCheck XDB
info-leak
CVE-2023-26083LOWunder attack28 May 2026
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost
58RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack27 May 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-9082CRITICALunder attack27 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-6340HIGHunder attack27 May 2026
Drupal core - Highly critical - Remote Code Execution
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-26980CRITICAL27 May 2026
Ghost has a SQL Injection in its Content API
85RISK
open
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALunder attack27 May 2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.