Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
8,722 exploits
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware18 Mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware18 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware18 Mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-29824HIGHunder attackransomware17 Mar 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-3248CRITICALunder attackransomware16 Mar 2026
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-9805HIGHunder attack16 Mar 2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware16 Mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALunder attackransomware15 Mar 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware15 Mar 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-27944CRITICAL14 Mar 2026
Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-49844CRITICAL13 Mar 2026
Redis Lua Use-After-Free may lead to remote code execution
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware13 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
client-side
CVE-2024-23222HIGHunder attack13 Mar 2026
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.
76RISK
open
VulnCheck XDB
initial-access
CVE-2025-12057CRITICAL13 Mar 2026
WavePlayer < 3.8.0 - Unauthenticated Arbitrary File Upload
48RISK
open
VulnCheck XDB
initial-access
CVE-2024-47176MEDIUM13 Mar 2026
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RISK
open
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALunder attackransomware12 Mar 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware12 Mar 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
client-side
CVE-2026-21509HIGHunder attack12 Mar 2026
Microsoft Office Security Feature Bypass Vulnerability
93RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware12 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-43208CRITICALunder attackransomware12 Mar 2026
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-31816CRITICAL12 Mar 2026
Budibase Universal Auth Bypass via Webhook Query Param Injection
68RISK
open
VulnCheck XDB
local
CVE-2024-21338HIGHunder attackransomware11 Mar 2026
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2019-10068CRITICALunder attack11 Mar 2026
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-6329CRITICAL11 Mar 2026
Control iD iDSecure passwordCustom Authentication Bypass
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-27944CRITICAL10 Mar 2026
Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure
68RISK
open
VulnCheck XDB
initial-access
CVE-2025-59287CRITICALunder attack09 Mar 2026
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-20127CRITICALunder attack09 Mar 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-33073HIGHunder attack09 Mar 2026
Windows SMB Client Elevation of Privilege Vulnerability
93RISK
open
VulnCheck XDB
client-side
CVE-2026-25253HIGH09 Mar 2026
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
41RISK
open
VulnCheck XDB
initial-access
CVE-2023-20198CRITICALunder attack08 Mar 2026
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.