Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,338cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
3,489 exploits
Metasploit600
SPIP X-Spip-Filtre Unauthenticated RCE
CVE-2026-77647CRITICAL20 Aug 2026
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
43RISK
open
Metasploit600
Tenable Security Center Report Charting RCE
CVE-2026-19626CRITICAL13 Aug 2026
Remote Code Execution
63RISK
open
Metasploit600
Tenable Security Center SCAP Audit File Command Injection
CVE-2026-19681CRITICAL13 Aug 2026
Command Injection
63RISK
open
Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
CVE-2025-24293CRITICAL29 Jul 2026
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
63RISK
open
Metasploit300
Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution
CVE-2026-66066CRITICAL29 Jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open
Metasploit600
JetBrains TeamCity Agent Polling Unauthenticated Remote Code Execution
CVE-2026-63077CRITICALunder attack27 Jul 2026
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
100RISK
open
Metasploit600
Check Point SmartConsole Authentication Bypass Run Script RCE
CVE-2026-16232CRITICALunder attack22 Jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open
Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
CVE-2026-60137MEDIUMunder attack17 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
CVE-2026-60137MEDIUMunder attack17 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
Metasploit600
WordPress WP2Shell REST API Batch Route Confusion SQLi to RCE
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
Metasploit600
Langflow AI auto_login RCE
CVE-2026-9198CRITICALunder attack17 Jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
Metasploit300
WordPress Core wp2shell Unauthenticated SQL Injection via REST Batch Route Confusion
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
Metasploit600
SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution
CVE-2026-15409CRITICALunder attackransomware14 Jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open
Metasploit300
Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)
CVE-2026-3576HIGH10 Jul 2026
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
61RISK
open
Metasploit600
Flowise MCP Server Remote Code Execution
CVE-2026-56274HIGH23 Jun 2026
Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess
36RISK
open
Metasploit600
Joomla Content Editor Unauthenticated File Upload RCE
CVE-2026-48907CRITICALunder attack05 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
Metasploit500
HP Poly Voice Unauthenticated Remote Code Execution
CVE-2026-0826CRITICAL01 Jun 2026
Poly Voice – Possible Remote Control of Certain Poly Devices
55RISK
open
Metasploit300
Concrete CMS Unauthenticated File Usage Disclosure
CVE-2026-6826MEDIUM21 May 2026
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
28RISK
open
Metasploit300
PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker
CVE-2026-0265HIGH21 May 2026
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RISK
open
Metasploit300
Drupal Core PostgreSQL EntityQuery SQL Injection
CVE-2026-9082CRITICALunder attack20 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
Metasploit300
Linux Kernel __ptrace_may_access() Exit Race chage File Disclosure
CVE-2026-46333HIGH14 May 2026
ptrace: slightly saner 'get_dumpable()' logic
56RISK
open
Metasploit500
Fragnesia LPE (CVE-2026-46300)
CVE-2026-46300HIGH14 May 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open
Metasploit400
xfrm-ESP Page-Cache Write via CVE-2026-43284
CVE-2026-43284HIGH08 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
Metasploit400
rxkad Page-Cache Write via CVE-2026-43500
CVE-2026-43500HIGH08 May 2026
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
78RISK
open
Metasploit600
Dalfox Found-Action Deserialization RCE
CVE-2026-45087CRITICAL07 May 2026
Dalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode
48RISK
open
Metasploit300
Cisco Catalyst SD-WAN Controller vHub Authentication Bypass
CVE-2026-20182CRITICALunder attack07 May 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
Metasploit600
Copy Fail AF_ALG + authencesn Page-Cache Write
CVE-2026-31431HIGHunder attack29 Apr 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
Metasploit600
Apache ActiveMQ RCE via Jolokia addNetworkConnector
CVE-2026-34197HIGHunder attack29 Apr 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISK
open
Metasploit600
cPanel/WHM CRLF Injection Authentication Bypass RCE
CVE-2026-41940CRITICALunder attackransomware28 Apr 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
Metasploit600
OpenCATS Installer PHP Code Injection
CVE-2026-27760CRITICAL28 Apr 2026
OpenCATS PHP Code Injection via installer AJAX endpoint
75RISK
open
page 1 / 117next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.