Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
8,829 exploits
VulnCheck XDB
denial-of-service
CVE-2026-6664HIGH12 May 2026
PgBouncer integer overflow in PgBouncer network packet parsing
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-2492CRITICAL12 May 2026
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req
48RISK
open
VulnCheck XDB
initial-access
CVE-2023-4220HIGH12 May 2026
Chamilo LMS Unauthenticated Big Upload File Remote Code Execution
78RISK
open
VulnCheck XDB
initial-access
CVE-2026-5718HIGH12 May 2026
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISK
open
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALunder attackransomware12 May 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
VulnCheck XDB
local
CVE-2024-0582HIGH12 May 2026
Kernel: io_uring: page use-after-free vulnerability via buffer ring mmap
46RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack11 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware11 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware11 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54068CRITICALunder attack11 May 2026
Livewire vulnerable to remote command execution during property update hydration
100RISK
open
VulnCheck XDB
local
CVE-2026-43284HIGH11 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
VulnCheck XDB
initial-access
CVE-2026-34486HIGHunder attack11 May 2026
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack11 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack11 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack11 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack11 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL11 May 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-1094HIGH10 May 2026
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
78RISK
open
VulnCheck XDB
info-leak
CVE-2026-42208CRITICALunder attack10 May 2026
LiteLLM: SQL injection in Proxy API key verification
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALunder attack10 May 2026
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-4396HIGH10 May 2026
Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection
56RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack10 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware10 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-3844CRITICAL10 May 2026
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
68RISK
open
VulnCheck XDB
local
CVE-2026-43284HIGH10 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
VulnCheck XDB
info-leak
CVE-2024-47176MEDIUM10 May 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack09 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-1938CRITICALunder attack09 May 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack09 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
client-side
CVE-2025-2783HIGHunder attack08 May 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.