Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
80,095 exploits
GitHub PoC21
TheCyberGeek/CVE-2026-4480-PoC
CVE-2026-4480CRITICAL05 Jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
GitHub PoC
t1ckprivate/CVE-2026-31431-Copy-Fail
CVE-2026-31431HIGHunder attack05 Jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-3300CRITICAL05 Jun 2026
Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
75RISK
open
GitHub PoC
cve-2026-23744 python exploit
CVE-2026-23744CRITICAL05 Jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL05 Jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
GitHub PoC
Exploit for Copy-Fail Vulnerability - Python3 Version
CVE-2026-31431HIGHunder attack05 Jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through the /api/mcp/connect endpoint.
CVE-2026-23744CRITICAL05 Jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
CVE-2026-23631-Draft
CVE-2026-23631MEDIUM04 Jun 2026
redis-server Lua use-after-free may allow remote code execution
33RISK
open
VulnCheck XDB
info-leak
CVE-2013-611704 Jun 2026
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISK
open
GitHub PoC29
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
CVE-2026-49975HIGH04 Jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISK
open
GitHub PoC2
Proof of Concept (PoC) exploit for CVE-2026-6815: Authenticated Path Traversal & Arbitrary File Write in Casdoor (< 3.54.1) leading to RCE/DoS.
CVE-2026-6815MEDIUM04 Jun 2026
CVE-2026-6815
33RISK
open
VulnCheck XDB
local
CVE-2026-31635HIGH04 Jun 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISK
open
GitHub PoC
PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)
CVE-2026-8732CRITICAL04 Jun 2026
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open
GitHub PoC
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
CVE-2026-35904CRITICAL04 Jun 2026
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
48RISK
open
GitHub PoC1
horrister/solarwinds-sunburst-cve-2020-10148
CVE-2020-10148CRITICALunder attack04 Jun 2026
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISK
open
GitHub PoC1
Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis. Python 3 stdlib-only, no network calls.
CVE-2026-42945CRITICAL04 Jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
CVE-2026-23744
CVE-2026-23744CRITICAL04 Jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
Improved Metasploit module for CVE-2013-6117 (Dahua DVR authentication bypass)
CVE-2013-611704 Jun 2026
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISK
open
VulnCheck XDB
initial-access
CVE-2026-34234CRITICAL04 Jun 2026
CtrlPanel: Unauthenticated RCE using installer script
48RISK
open
GitHub PoC
CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser
CVE-2026-50142HIGH04 Jun 2026
libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)
41RISK
open
VulnCheck XDB
info-leak
CVE-2024-1698CRITICAL04 Jun 2026
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open
GitHub PoC
CVE-2026-45247 - Draft
CVE-2026-45247CRITICALunder attack04 Jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISK
open
GitHub PoC
HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then extract MinIO credentials from admin settings. Use CVE-2024-46987 path traversal to steal an SSH private key, crack its passphrase, and escalate to root by abusing sudo permissions on facter via GTFOBins.
CVE-2024-46987HIGH04 Jun 2026
Arbitrary path traversal in Camaleon CMS
61RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL04 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL04 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
rootdirective-sec/CVE-2026-34234-Lab
CVE-2026-34234CRITICAL04 Jun 2026
CtrlPanel: Unauthenticated RCE using installer script
48RISK
open
GitHub PoC
Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE
CVE-2026-4883CRITICAL04 Jun 2026
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload
48RISK
open
GitHub PoC13
Attack surface in the real-world environment of CVE-2026-41096
CVE-2026-41096CRITICAL04 Jun 2026
Windows DNS Client Remote Code Execution Vulnerability
48RISK
open
GitHub PoC
CVE-2026-5076 — ARMember Premium <= 7.3.1 Insecure Password Reset Mechanism → Full Admin Account Takeover | Proof of Concept
CVE-2026-5076CRITICAL04 Jun 2026
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
48RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-41089CRITICAL04 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
previouspage 105 / 2,670next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.