Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
8,722 exploits
VulnCheck XDB
local
CVE-2024-1086HIGHunder attackransomware30 Mar 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-54123CRITICAL30 Mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware29 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-54123CRITICAL29 Mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open
VulnCheck XDB
info-leak
CVE-2026-26980CRITICAL29 Mar 2026
Ghost has a SQL Injection in its Content API
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL29 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware28 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-33045CRITICALunder attack28 Mar 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-54123CRITICAL28 Mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-54123CRITICAL28 Mar 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL28 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
local
CVE-2026-23744CRITICAL28 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
info-leak
CVE-2026-21643CRITICALunder attack28 Mar 2026
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL27 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-6440CRITICAL27 Mar 2026
WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload
60RISK
open
VulnCheck XDB
info-leak
CVE-2026-21643CRITICALunder attack27 Mar 2026
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-15030CRITICAL27 Mar 2026
User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack27 Mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL27 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL27 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
client-side
CVE-2024-26229HIGH27 Mar 2026
Windows CSC Service Elevation of Privilege Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack26 Mar 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL26 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2025-20282CRITICAL26 Mar 2026
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
68RISK
open
VulnCheck XDB
initial-access
CVE-2019-25065MEDIUM26 Mar 2026
OpenNetAdmin os command injection
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack26 Mar 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack26 Mar 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-23744CRITICAL25 Mar 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-3584CRITICAL25 Mar 2026
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
63RISK
open
VulnCheck XDB
local
CVE-2024-51324LOW25 Mar 2026
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via ex
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.