Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,957cataloged exploits
32,195CVEs with public exploitation
1,932lab-tested
71,886 exploits
VulnCheck XDB
remote-with-credentials
CVE-2026-34197HIGHunder attack08 Apr 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-9276HIGHunder attack07 Apr 2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-0740CRITICAL07 Apr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC
e1st/CVE-2025-56015
CVE-2025-56015HIGH07 Apr 2026
In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
41RISK
open
GitHub PoC
Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.
CVE-2011-252307 Apr 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC1
Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)
CVE-2026-0740CRITICAL07 Apr 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack07 Apr 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
thorat-shubham/JXL_Infotainment_CVE-2025-69515
CVE-2025-69515CRITICAL07 Apr 2026
An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int
48RISK
open
GitHub PoC
sathish46-lab/CVE-2025-48384-submodule
CVE-2025-48384HIGHunder attack07 Apr 2026
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC1
Apache Tomcat(CVE-2020-1938)漏洞验证脚本
CVE-2020-1938CRITICALunder attack07 Apr 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
Este script es para uso educativo y en entornos autorizados como HackTheBox. El uso contra sistemas sin permiso explícito es ilegal.
CVE-2025-9074CRITICAL07 Apr 2026
Docker Desktop allows unauthenticated access to Docker Engine API from containers
48RISK
open
GitHub PoC
CVE-2025-13315
CVE-2025-13315CRITICAL07 Apr 2026
Unauthenticated log access in Twonky Server
75RISK
open
GitHub PoC
Python Exploit for CVE: 2018-9276
CVE-2018-9276HIGHunder attack07 Apr 2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
GitHub PoC
CVE-2025-8088 is a critical path traversal vulnerability in WinRAR 7.12
CVE-2025-8088HIGHunder attack07 Apr 2026
Path traversal vulnerability in WinRAR
93RISK
open
VulnCheck XDB
info-leak
CVE-2025-13315CRITICAL07 Apr 2026
Unauthenticated log access in Twonky Server
75RISK
open
GitHub PoC
CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-32646HIGH07 Apr 2026
Gardyn Cloud API Missing Authentication for Critical Function
41RISK
open
GitHub PoC
CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-28766CRITICAL07 Apr 2026
Gardyn Cloud API Missing Authentication for Critical Function
48RISK
open
GitHub PoC
CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)
CVE-2025-10681HIGH07 Apr 2026
Gardyn Mobile Application and Device Firmware Use Hard-coded Credentials
41RISK
open
GitHub PoC
CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-25197CRITICAL07 Apr 2026
Gardyn Cloud API Authorization Bypass Through User-Controlled Key
48RISK
open
GitHub PoC
CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-28767MEDIUM07 Apr 2026
Gardyn Cloud API Missing Authentication for Critical Function
33RISK
open
GitHub PoC
CVE-2026-32662: Active Debug Code in Production — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-32662MEDIUM07 Apr 2026
Gardyn Cloud API Active Debug Code
33RISK
open
GitHub PoC5
PoC for CVE-2026-13585
CVE-2026-13585HIGH07 Apr 2026
Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in
41RISK
open
VulnCheck XDB
info-leak
CVE-2020-1938CRITICALunder attack07 Apr 2026
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RISK
open
GitHub PoC
zsxen/CVE-2025-1974
CVE-2025-1974CRITICAL06 Apr 2026
ingress-nginx admission controller RCE escalation
85RISK
open
Exploit-DB
ASP.net 8.0.10 - Bypass
CVE-2025-55315CRITICAL06 Apr 2026
ASP.NET Security Feature Bypass Vulnerability
60RISK
open
GitHub PoC
PoC: CVE-2025-30065 incomplete fix bypass in Apache Parquet Java 1.15.1
CVE-2025-30065CRITICAL06 Apr 2026
Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
60RISK
open
Exploit-DB
Fortinet FortiWeb v8.0.1 - Auth Bypass
CVE-2025-64446CRITICALunder attack06 Apr 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
avitoriagomes/CVE-2024-29988
CVE-2024-29988HIGHunder attack06 Apr 2026
SmartScreen Prompt Security Feature Bypass Vulnerability
83RISK
open
GitHub PoC
zsxen/cve-2025-1974-lab
CVE-2025-1974CRITICAL06 Apr 2026
ingress-nginx admission controller RCE escalation
85RISK
open
GitHub PoC1
End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to mitigate CVE-2025-14847.
CVE-2025-14847HIGHunder attack06 Apr 2026
Zlib compressed protocol header length confusion may allow memory read
100RISK
open
previouspage 95 / 2,397next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.