Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,886cataloged exploits
32,153CVEs with public exploitation
1,932lab-tested
71,836 exploits
GitHub PoC
Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Passive HTTP metadata auditor for CVE-2026-23918 exposure triage
CVE-2026-23918HIGH05 May 2026
Apache HTTP Server: http2: double free and possible RCE on early reset
53RISK
open
GitHub PoC
Analysis of CVE-2026-24072
CVE-2026-24072HIGH05 May 2026
Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
21RISK
open
GitHub PoC
One IPv6 ND option with length zero. One missing check. Daemon walks backward and lives in the loop. Reported to OpenBSD, fixed, CVE assigned.
CVE-2026-41285MEDIUM05 May 2026
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Dis
13RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-43284HIGH05 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2025-21333HIGHunder attack05 May 2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
Detection signatures for CVE-2026-41940 and shemas for cPanel logs
CVE-2026-41940CRITICALunder attackransomware05 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC22
LPE due to integer truncation in vskrnlintvsp.sys
CVE-2025-21333HIGHunder attack05 May 2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
Утилита для Linux, которая проверяет доступность `AF_ALG`/`algif_aead` и помогает оценить риск по `CVE-2026-31431`.
CVE-2026-31431HIGHunder attack05 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALunder attack05 May 2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-7482HIGH05 May 2026
Ollama heap out-of-bounds read in GGUF tensor parsing leaks server process memory to unauthenticated remote attackers
21RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware05 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-41940CRITICALunder attackransomware05 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
ZildanZ/CVE-2026-41940
CVE-2026-41940CRITICALunder attackransomware05 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico
CVE-2021-44228CRITICALunder attackransomware05 May 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico
CVE-2014-6271CRITICALunder attack05 May 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Simple exploit
CVE-2022-22963CRITICALunder attack05 May 2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RISK
open
Exploit-DB
MindsDB 25.9.1.1 - Path Traversal
CVE-2026-27483HIGH04 May 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RISK
open
GitHub PoC10
Safe detection tooling for CVE-2026-31431 "Copy Fail" and CVE-2026-43284 "Dirty Frag" — a local privilege escalation in the Linux kernel's algif_aead module affecting all major distributions since 2017.
CVE-2026-31431HIGHunder attack04 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
kaleth4/CVE-2025-47987
CVE-2025-47987HIGH04 May 2026
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2025-69985CRITICAL04 May 2026
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnera
48RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack04 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack04 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
previouspage 75 / 2,395next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.