Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
24,466 exploits
Exploit-DB
Metabase 0.61.0 - Authenticated Remote Code Execution
CVE-2026-59827CRITICALwebappsmultiple03 Sep 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RISK
open
Exploit-DB
Langflow 1.10.0 - RCE
CVE-2026-9198CRITICALunder attackwebappsmultiple02 Sep 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
Exploit-DB
Grav CMS 2.0.7 - RCE
CVE-2026-65008CRITICALwebappsmultiple01 Sep 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISK
open
Exploit-DB
Wolf CMS 0.8.3.1 - RCE v
CVE-2026-67206HIGHwebappsmultiple01 Sep 2026
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RISK
open
Exploit-DB
EasyAppointments 1.5.1 - Blind SQL Injection
CVE-2025-50455CRITICALwebappsmultiple01 Sep 2026
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp
48RISK
open
Exploit-DB
miniOrange 5.4.3 - Unauthenticated Auth Bypass
CVE-2026-15013CRITICALwebappsmultiple01 Sep 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISK
open
Exploit-DB
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
CVE-2026-42167HIGHremotemultiple25 Aug 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISK
open
Exploit-DB
PCMan 2.0.7 - Buffer Overflow
CVE-2025-4871MEDIUMremotewindows18 Aug 2026
PCMan FTP Server REST Command buffer overflow
33RISK
open
Exploit-DB
webpack_devserver 5.2.5 - CSRF
CVE-2026-14620MEDIUMwebappsmultiple17 Aug 2026
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
33RISK
open
Exploit-DB
NanaZip 6.5 - DoS
CVE-2026-55780LOWdoswindows17 Aug 2026
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
28RISK
open
Exploit-DB
Joomla JCE_2.9.15 - Remote Code Execution
CVE-2026-48907CRITICALunder attackwebappsmultiple17 Aug 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
Exploit-DB
D-Link DNS_340L - OS Command Injection
CVE-2024-10914CRITICALremotehardware17 Aug 2026
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RISK
open
Exploit-DB
Nmap 7.99 - Extension Header Integer Underflow
CVE-2026-58058MEDIUMdosmultiple17 Aug 2026
Nmap - Integer Underflow in IPv6 Extension Header Parsing
33RISK
open
Exploit-DB
phpSysInfo 3.4.5 - IP Allowlist Bypass
CVE-2026-55584HIGHremotelinux17 Aug 2026
phpSysInfo: IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
41RISK
open
Exploit-DB
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
CVE-2026-3891CRITICALwebappsmultiple17 Aug 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
Exploit-DB
Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
CVE-2026-3576HIGHwebappsmultiple11 Aug 2026
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
61RISK
open
Exploit-DB
Blocksy Companion 2.1.46 - RCE
CVE-2026-58480CRITICALwebappsmultiple11 Aug 2026
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
48RISK
open
Exploit-DB
mcp-server-kubernetes 3.8.x - Argument Injection
CVE-2026-61459CRITICALremotemultiple11 Aug 2026
MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools
48RISK
open
Exploit-DB
LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
CVE-2026-61876CRITICALdosmultiple11 Aug 2026
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting
48RISK
open
Exploit-DB
PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
CVE-2026-61447CRITICALremotemultiple11 Aug 2026
PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
48RISK
open
Exploit-DB
Joomla 2.9.99.4 - Unauthenticated Remote Code Execution
CVE-2026-48907CRITICALunder attackwebappsmultiple10 Aug 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
Exploit-DB
Microsoft Edge 150.0.4078.48 - RCE
CVE-2026-58289CRITICALlocalmultiple10 Aug 2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
48RISK
open
Exploit-DB
OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
CVE-2026-58138CRITICALwebappsmultiple10 Aug 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
Exploit-DB
Krayin CRM v2.2.x - Authenticated Remote Code Execution
CVE-2026-38526CRITICALwebappsmultiple08 Jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
Exploit-DB
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
CVE-2026-56290CRITICALwebappsmultiple08 Jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISK
open
Exploit-DB
Langflow 1.9.0 - RCE
CVE-2026-33017CRITICALunder attackwebappsmultiple08 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
Exploit-DB
Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
CVE-2025-60188HIGHwebappsmultiple08 Jul 2026
WordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
56RISK
open
Exploit-DB
MCPJam Inspector - Remote Code Execution
CVE-2026-23744CRITICALwebappsmultiple07 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
Exploit-DB
Tenable Nessus 10.12.1 - SQL Injection
CVE-2026-57588LOWwebappsmultiple07 Jul 2026
SQL Injection in Nessus via Malicious Scan Result File Import
28RISK
open
Exploit-DB
WordPress Bricks Builder Theme - RCE
CVE-2024-25600CRITICALwebappsmultiple07 Jul 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
page 1 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.