Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
14,997 exploits
GitHub PoC
Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
100RISK
open ↗GitHub PoC
willygailo/WG-CVE-2026-1555-Linux
WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
48RISK
open ↗GitHub PoC★ 1
CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open ↗GitHub PoC★ 1
Mitigation scripts for CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open ↗GitHub PoC
CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload
Microsoft Word Remote Code Execution Vulnerability
70RISK
open ↗GitHub PoC★ 1
smb spooler to RCE
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open ↗GitHub PoC
Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗GitHub PoC
YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open ↗GitHub PoC★ 2
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust server memory. It affects default HTTP/2 configurations of **nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora**.
Apache HTTP Server: mod_http2 denial of service
53RISK
open ↗GitHub PoC
rootdirective-sec/CVE-2026-7465-Lab
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
41RISK
open ↗GitHub PoC
Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)
Apache Tomcat: Digest authenticator will authenticate any unknown user
48RISK
open ↗GitHub PoC★ 3
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open ↗GitHub PoC
GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open ↗GitHub PoC★ 2
Account takeover full PoC for CVE-2026-27886 in Strapi CMS
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
48RISK
open ↗GitHub PoC
carlosalbertotuma/cve-2026-3180-poc
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RISK
open ↗GitHub PoC
Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗GitHub PoC★ 1
CVE-2026-4480
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open ↗GitHub PoC
m0nk3ygod/CVE-2026-34040-PoC
Moby: AuthZ plugin bypass with oversized request body
41RISK
open ↗GitHub PoC★ 2
FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗GitHub PoC★ 1
Exploit CVE-2026-4480
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open ↗GitHub PoC
Drupal Core PostgreSQL SQLi to RCE via /user/login (CVE-2026-9082 / SA-CORE-2026-004)
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open ↗GitHub PoC
Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell for remote code execution.
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗GitHub PoC★ 1
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
63RISK
open ↗GitHub PoC
t1ckprivate/CVE-2022-0847-Dirty-Pipe
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISK
open ↗GitHub PoC
HTTP/2 attack simulation & defense lab - Slowloris, Rapid Reset (CVE-2023-44487), HPACK Bomb attacks with 5 layered defenses. Built in pure Python with raw sockets and h2 library.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗GitHub PoC★ 6
🚀 CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control 💥 CRLF injection via NEW_ENVIRON leads to auth bypass & instant root shell. ✅ Single/Mass exploitation, multi-threading, custom port/user, pipe mode, session keep-alive, colored output, retries, timeout support. ⚡ Python & Bash versions. Critical CVSS 9.8.
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open ↗GitHub PoC★ 1
CVE-2026-76060 PoC for a ZoneMinder vulnerability leading to RCE
OS Command Injection in PayRange API
41RISK
open ↗GitHub PoC★ 7
CVE-2025-57819 -> rce
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗GitHub PoC
Apache ActiveMQ RCE via Jolokia vulnerability analysis and reproduction notes
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.