Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
79,980 exploits
GitHub PoC
CVE-2025-57819 FreePBX SQLi RCE PoC
CVE-2025-57819CRITICALunder attack24 Jun 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALunder attack24 Jun 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC
CraftCMS CVE-2025-32432 - Clean PoC
CVE-2025-32432CRITICALunder attack24 Jun 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC63
CVE-2026-45504 Microsoft Exchange File Read
CVE-2026-45504HIGH24 Jun 2026
Microsoft Exchange Server Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
ROOT TOOL
CVE-2022-37706HIGH24 Jun 2026
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISK
open
GitHub PoC28
CVE-2026-42978 — Use-After-Free race condition in Windows Push Notifications (WpnService). Patch diff, root cause analysis, TOCTOU lab, Sysmon/ETW detection rules.
CVE-2026-42978HIGH23 Jun 2026
Windows Push Notifications Elevation of Privilege Vulnerability
41RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware23 Jun 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC8
anyanything/CVE-2026-8461-PoC
CVE-2026-8461HIGH23 Jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RISK
open
GitHub PoC10
CVE-2026-55200
CVE-2026-55200CRITICAL23 Jun 2026
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RISK
open
GitHub PoC
Public advisory for CVE-2026-39253, addressing an insecure deserialisation in Pivotal CRM 6.6.04.08 allowing remote code execution via unsafe BinaryFormatter usage in Smart Client and PBS components. Includes vulnerability details, affected versions, and remediation guidance.
CVE-2026-39253HIGH23 Jun 2026
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a
41RISK
open
GitHub PoC1
A minimal PoC for CVE-2026-21018, demonstrating how it works
CVE-2026-21018MEDIUM23 Jun 2026
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary
33RISK
open
GitHub PoC
s1lentf00thold/CVE-2021-21425-RCE
CVE-2021-21425CRITICAL23 Jun 2026
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
85RISK
open
GitHub PoC4
Proof of Concept (PoC) for the TP-Link DHCP Option 66 Unauthenticated RCE (CVE-2026-11834)
CVE-2026-11834HIGH23 Jun 2026
Unauthenticated Command Injection via DHCP Option Handling in Multiple TP-Link Routers
41RISK
open
GitHub PoC
mythicaltree/CVE-2019-2215
CVE-2019-2215HIGHunder attack23 Jun 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC
eliHiHo/portfolio-drupal-cve-2026-9082
CVE-2026-9082CRITICALunder attack23 Jun 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-023223 Jun 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
Metasploit600
Flowise MCP Server Remote Code Execution
CVE-2026-56274HIGH23 Jun 2026
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
36RISK
open
GitHub PoC
Apache Tomcat CGI Servlet RCE (Windows)
CVE-2019-023223 Jun 2026
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
VulnCheck XDB
local
CVE-2019-2215HIGHunder attack23 Jun 2026
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open
GitHub PoC
fuchiuebusi-lab/nginx-ui-CVE-2026-42221-CVE-2026-42238-
CVE-2026-42221HIGH23 Jun 2026
nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
56RISK
open
GitHub PoC
s1lentf00thold/CVE-2020-11651-Poc
CVE-2020-11651CRITICALunder attack23 Jun 2026
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALunder attack23 Jun 2026
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RISK
open
GitHub PoC2
This repository contains the Proof of Concept (PoC) exploit script for CVE-2026-45156
CVE-2026-45156HIGH23 Jun 2026
Nextcloud: Authentication Bypass in ID4me handling via Missing JWT Signature Verification in User OIDC
41RISK
open
GitHub PoC
Prueba de concepto de CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware23 Jun 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of CVE-2024-9902.
CVE-2026-11837HIGH23 Jun 2026
Ansible-collection-ansible-posix: ansible.posix authorized_key: local privilege escalation via symlink-following chown
41RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack23 Jun 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.
CVE-2026-41096CRITICAL23 Jun 2026
Windows DNS Client Remote Code Execution Vulnerability
48RISK
open
GitHub PoC
CVE-2026-40369本地权限提升漏洞exp
CVE-2026-40369HIGH23 Jun 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC86
Proof of Concept (PoC) demonstrating the CVE-2026-18220, an out-of-bounds (OOB) write vulnerability in the DLX ELF backend of GNU binutils (specifically triggered via `objdump -g`)
CVE-2026-18220HIGH22 Jun 2026
Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALunder attack22 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
previouspage 84 / 2,666next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.