Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
8,829 exploits
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL18 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
VulnCheck XDB
local
CVE-2025-21479HIGHunder attack17 Aug 2026
Incorrect Authorization in Graphics
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack17 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL17 Aug 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware17 Aug 2026
Argument Injection in PHP-CGI
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-59310CRITICALunder attack17 Aug 2026
vCenter directory-traversal vulnerability
90RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware17 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-72898CRITICALunder attack17 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2017-7494CRITICALunder attackransomware17 Aug 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
VulnCheck XDB
local
CVE-2018-8611HIGHunder attack17 Aug 2026
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
71RISK
open
VulnCheck XDB
client-side
CVE-2020-6418HIGHunder attack16 Aug 2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware15 Aug 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-72898CRITICALunder attack15 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-8452HIGHunder attack14 Aug 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-31816CRITICAL14 Aug 2026
Budibase Universal Auth Bypass via Webhook Query Param Injection
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-32433CRITICALunder attack14 Aug 2026
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware14 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
local
CVE-2026-46300HIGH14 Aug 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack14 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack14 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware14 Aug 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware14 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware13 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
local
CVE-2024-21413CRITICALunder attack12 Aug 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-4808412 Aug 2026
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
50RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware12 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-48710MEDIUM12 Aug 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack12 Aug 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-48908CRITICAL12 Aug 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open
VulnCheck XDB
local
CVE-2023-32233HIGH12 Aug 2026
In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused
46RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.