Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
80,095 exploits
GitHub PoC
1-day exploit for CVE-2026-49417
CVE-2026-49417HIGH10 Jun 2026
Multiple vulnerabilities in the sound(4) mmap path
41RISK
open
GitHub PoC
Dhananjayasj/CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-
CVE-2025-24813CRITICALunder attack10 Jun 2026
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RISK
open
GitHub PoC1
OSCP like CVE-2025-24893 exploit for Linux XWiki
CVE-2025-24893CRITICALunder attack10 Jun 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-3721MEDIUM10 Jun 2026
TBK DVR-4104/DVR-4216 os command injection
55RISK
open
GitHub PoC
CVE-2026-48962 - IO::Compress - Code Execution
CVE-2026-48962HIGH10 Jun 2026
IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
41RISK
open
GitHub PoC6
watchtowrlabs/watchTowr-vs-Check-Point-CVE-2026-50751
CVE-2026-50751CRITICALunder attackransomware10 Jun 2026
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open
GitHub PoC2
HTTP.sys RCE
CVE-2026-47291CRITICAL10 Jun 2026
HTTP.sys Remote Code Execution Vulnerability
33RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-28318HIGHunder attack10 Jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RISK
open
GitHub PoC
jenniferreire26/CVE-2026-28318
CVE-2026-28318HIGHunder attack09 Jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RISK
open
VulnCheck XDB
initial-access
CVE-2026-45247CRITICALunder attack09 Jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISK
open
GitHub PoC1
Insert PHP Plugin PHP Code Injection
CVE-2017-20251CRITICAL09 Jun 2026
WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
48RISK
open
GitHub PoC
jenniferreire26/CVE-2026-33829
CVE-2026-33829MEDIUM09 Jun 2026
Windows Snipping Tool Spoofing Vulnerability
33RISK
open
GitHub PoC
jenniferreire26/CVE-2026-45659
CVE-2026-45659HIGHunder attackransomware09 Jun 2026
Microsoft SharePoint Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
dotCMS Pre-auth SQL Injection
CVE-2026-8054CRITICAL09 Jun 2026
Unauthenticated SQL Injection in dotCMS Publish Audit API
63RISK
open
GitHub PoC
jenniferreire26/CVE-2026-23479
CVE-2026-23479HIGH09 Jun 2026
redis-server use-after-free in unblock client flow may allow remote code execution
41RISK
open
GitHub PoC
Go Proof of Concept (PoC) exploit for Flowise CustomMCP Remote Code Execution (RCE) CVE-2025-59528
CVE-2025-59528CRITICAL09 Jun 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
GitHub PoC
jenniferreire26/CVE-2026-42945
CVE-2026-42945CRITICAL09 Jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
jenniferreire26/CVE-2026-48595
CVE-2026-48595HIGH09 Jun 2026
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
21RISK
open
GitHub PoC
Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).
CVE-2026-47429CRITICAL09 Jun 2026
Vitest: Arbitrary file can be read and executed when Vitest UI server is listening
48RISK
open
GitHub PoC
jenniferreire26/CVE-2026-35616
CVE-2026-35616CRITICALunder attack09 Jun 2026
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RISK
open
GitHub PoC
rootdirective-sec/CVE-2025-11262-Lab
CVE-2025-11262HIGH09 Jun 2026
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
41RISK
open
GitHub PoC
CVE-2024-52011 - Draft
CVE-2024-52011HIGH09 Jun 2026
launch-editor vulnerable to command injection via the crafted request on Windows
41RISK
open
GitHub PoC
CVE-2026-42271 - Draft
CVE-2026-42271HIGHunder attack09 Jun 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RISK
open
GitHub PoC
PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.
CVE-2026-46394HIGH09 Jun 2026
HAX CMS Vulnerable to Command Injection using Git.php
41RISK
open
GitHub PoC
PoC and writeup for CVE-2026-46395: unauthenticated private key disclosure via broken HMAC in HAXcms Node.js (CWE-321/CWE-200). Authorized security research only.
CVE-2026-46395CRITICAL09 Jun 2026
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
48RISK
open
GitHub PoC1
Proof-of-concept demonstrating cross-user X11 session compromise in Pardus LightDM Greeter caused by the unsafe `xhost +local:` configuration, including unauthorized shell access, display access, screen capture, window enumeration, and XTEST input injection.
CVE-2026-79617HIGH09 Jun 2026
Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
41RISK
open
GitHub PoC
Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque até RCE e miniguia de hardening
CVE-2024-42327CRITICAL09 Jun 2026
SQL injection in user.get API
70RISK
open
GitHub PoC
CVE-2026-45067 - Draft
CVE-2026-45067MEDIUM09 Jun 2026
Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
33RISK
open
GitHub PoC
jenniferreire26/CVE-2026-41089
CVE-2026-41089CRITICAL09 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL09 Jun 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
previouspage 100 / 2,670next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.