Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
80,057 exploits
GitHub PoC
CVE-2026-20262 - Draft
CVE-2026-20262MEDIUMunder attack16 Jun 2026
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
68RISK
open
VulnCheck XDB
info-leak
CVE-2024-23897CRITICALunder attackransomware16 Jun 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC62
CVE-2026-41940 exploitation proof-of-concept project
CVE-2026-41940CRITICALunder attackransomware16 Jun 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-40217HIGH16 Jun 2026
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t
61RISK
open
GitHub PoC1
A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132
CVE-2025-49132CRITICAL16 Jun 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-50751CRITICALunder attackransomware16 Jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
VulnCheck XDB
info-leak
CVE-2025-49132CRITICAL16 Jun 2026
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
75RISK
open
GitHub PoC
Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.
CVE-2024-23897CRITICALunder attackransomware16 Jun 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC1
PoC exploit for CVE-2025-55182 (React2Shell) — Pre-auth RCE in React Server Components | CVSS 10.0
CVE-2025-55182CRITICALunder attackransomware16 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2026-50751 Mass Scanner
CVE-2026-50751CRITICALunder attackransomware16 Jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware16 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
KovachVL/CVE-2026-55168
CVE-2026-55168MEDIUM16 Jun 2026
Runtipi: Authenticated arbitrary file write via backup restore symlink planting
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL16 Jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
GitHub PoC
CVE-2026-47101, CVE-2026-47102, CVE-2026-40217
CVE-2026-47101HIGH16 Jun 2026
LiteLLM < 1.83.14 Privilege Escalation via API Key Generation
41RISK
open
GitHub PoC
Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open
CVE-2003-020116 Jun 2026
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISK
open
GitHub PoC7
Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.
CVE-2026-45585MEDIUM16 Jun 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
GitHub PoC
0xdak/CVE-2026-44881_exploit
CVE-2026-44881HIGH16 Jun 2026
Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update
41RISK
open
GitHub PoC1
Mass Scanner For Drupal Exploit CVE-2026-9082
CVE-2026-9082CRITICALunder attack16 Jun 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC2
mahfuzreham/litespeed-cpanel-cve-2026-54420-fix
CVE-2026-54420HIGHunder attack16 Jun 2026
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provide
71RISK
open
GitHub PoC1
CVE-2026-54420
CVE-2026-54420HIGHunder attack16 Jun 2026
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provide
71RISK
open
GitHub PoC
This is an exploit poc for CVE-2026-4480
CVE-2026-4480CRITICAL16 Jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
GitHub PoC
rootdirective-sec/CVE-2026-10795-Lab
CVE-2026-10795HIGH15 Jun 2026
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
41RISK
open
GitHub PoC
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.
CVE-2026-37070MEDIUM15 Jun 2026
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated
33RISK
open
VulnCheck XDB
client-side
CVE-2025-2783HIGHunder attack15 Jun 2026
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
71RISK
open
GitHub PoC
User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.
CVE-2026-37064MEDIUM15 Jun 2026
User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker
33RISK
open
GitHub PoC3
PoC exploit for CVE-2026-53519.
CVE-2026-53519CRITICAL15 Jun 2026
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
63RISK
open
GitHub PoC2
DylanZahedi/CVE-2026-9277
CVE-2026-9277CRITICAL15 Jun 2026
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
48RISK
open
GitHub PoC
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.
CVE-2026-37067MEDIUM15 Jun 2026
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauth
33RISK
open
GitHub PoC
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.
CVE-2026-37068HIGH15 Jun 2026
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allow
41RISK
open
GitHub PoC
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.
CVE-2026-37073MEDIUM15 Jun 2026
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated a
33RISK
open
previouspage 92 / 2,669next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.