Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
71,886 exploits
GitHub PoC7
Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.
CVE-2024-51482CRITICAL28 Apr 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC
B1gN0Se/PwnKit_CVE-2021-4034
CVE-2021-4034HIGHunder attack28 Apr 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
kaleth4/CVE-2021-44228
CVE-2021-44228CRITICALunder attackransomware27 Apr 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC1
melikesraoz/cve-2022-39227-jwt-auth-bypass-demo
CVE-2022-39227CRITICAL27 Apr 2026
Python-jwt subject to Authentication Bypass by Spoofing
48RISK
open
GitHub PoC
Analysis and PoC for CVE-2018-14847, MikroTik RouterOS Winbox information disclosure vulnerability allowing unauthenticated read access to the credential database.
CVE-2018-14847CRITICALunder attack27 Apr 2026
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC
Multiple CVEs (CVE-2026-38934, CVE-2026-38935, CVE-2026-38936) discovered in diskover-community including CSRF and XSS vulnerabilities with proof-of-concept and impact analysis.
CVE-2026-38934HIGH27 Apr 2026
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker
41RISK
open
VulnCheck XDB
info-leak
CVE-2018-14847CRITICALunder attack27 Apr 2026
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC
A black box penetration test on HackTheBox's CCTV machine achieving full root compromise via four vulnerabilities: default credentials, SQL injection (CVE-2024-51482), password hash cracking, and Remote Code Execution in motionEye (CVE-2025-60787)
CVE-2025-60787HIGH26 Apr 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack26 Apr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
GitHub PoC
A black box penetration test on HackTheBox's CCTV machine achieving full root compromise via four vulnerabilities: default credentials, SQL injection (CVE-2024-51482), password hash cracking, and Remote Code Execution in motionEye (CVE-2025-60787)
CVE-2024-51482CRITICAL26 Apr 2026
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RISK
open
GitHub PoC
patch-manager
CVE-2019-1428725 Apr 2026
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RISK
open
GitHub PoC
Some Proof-of-Concept (POCs) for CVE-2025-29927, CVE-2026-27978, and CVE-2026-29057 in Next.js.
CVE-2025-29927CRITICAL25 Apr 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution, post-exploitation steps, and full pentesting report.
CVE-2019-9978MEDIUMunder attack25 Apr 2026
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RISK
open
GitHub PoC
CMS Simple CVE Recode Script Python 3
CVE-2019-905325 Apr 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
VulnCheck XDB
local
CVE-2023-32629HIGH25 Apr 2026
Local privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks
56RISK
open
GitHub PoC
Cybersecurity-Enthusiasts-CE/CVE-2025-55182-Researching-process
CVE-2025-55182CRITICALunder attackransomware25 Apr 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
DONKEY0xSHOT/CVE-2017-11882-Blocker
CVE-2017-11882HIGHunder attackransomware25 Apr 2026
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open
GitHub PoC
CVE-2024-3273 — Authorized Penetration Test Report D-Link DNS-320L NAS | Client: Otonata
CVE-2024-3273HIGHunder attack25 Apr 2026
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware25 Apr 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
bhatbhupendra/Moniker-Link--CVE-2024-21413-
CVE-2024-21413CRITICALunder attack25 Apr 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-39987CRITICALunder attack25 Apr 2026
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-3844CRITICAL25 Apr 2026
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL25 Apr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC1
im2sinister/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware25 Apr 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
LoGGGG2402/CVE-2025-27407
CVE-2025-27407CRITICAL25 Apr 2026
Remote code execution when loading a crafted GraphQL schema
48RISK
open
GitHub PoC
HTB Season 10 - Pterodactyl machine writeup. Medium Linux box covering CVE-2025-49132 (Pterodactyl Panel RCE) and CVE-2025-6018/6019 (udisks2 privilege escalation).
CVE-2025-49132CRITICAL24 Apr 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-3844CRITICAL24 Apr 2026
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-3844CRITICAL24 Apr 2026
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-3844CRITICAL24 Apr 2026
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-21962CRITICAL24 Apr 2026
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo
60RISK
open
previouspage 86 / 2,397next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.