Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,095cataloged exploits
36,945CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,442GitHub PoC 15,312VulnCheck XDB 8,970Nuclei 4,393Metasploit 3,502✓ verified onlyrecentpopularrisk
80,095 exploits
GitHub PoC★ 21
TheCyberGeek/CVE-2026-4480-PoC
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open ↗GitHub PoC
t1ckprivate/CVE-2026-31431-Copy-Fail
crypto: algif_aead - Revert to operating out-of-place
100RISK
open ↗VulnCheck XDB
initial-access
Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
75RISK
open ↗GitHub PoC
cve-2026-23744 python exploit
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open ↗VulnCheck XDB
initial-access
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open ↗GitHub PoC
Exploit for Copy-Fail Vulnerability - Python3 Version
crypto: algif_aead - Revert to operating out-of-place
100RISK
open ↗GitHub PoC
This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through the /api/mcp/connect endpoint.
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open ↗GitHub PoC
CVE-2026-23631-Draft
redis-server Lua use-after-free may allow remote code execution
33RISK
open ↗VulnCheck XDB
info-leak
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISK
open ↗GitHub PoC★ 29
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
Apache HTTP Server: mod_http2 denial of service
53RISK
open ↗GitHub PoC★ 2
Proof of Concept (PoC) exploit for CVE-2026-6815: Authenticated Path Traversal & Arbitrary File Write in Casdoor (< 3.54.1) leading to RCE/DoS.
CVE-2026-6815
33RISK
open ↗GitHub PoC
PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
68RISK
open ↗GitHub PoC
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an
48RISK
open ↗GitHub PoC★ 1
horrister/solarwinds-sunburst-cve-2020-10148
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RISK
open ↗GitHub PoC★ 1
Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis. Python 3 stdlib-only, no network calls.
NGINX ngx_http_rewrite_module vulnerability
60RISK
open ↗GitHub PoC
Improved Metasploit module for CVE-2013-6117 (Dahua DVR authentication bypass)
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RISK
open ↗GitHub PoC
CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser
libheif: unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check)
41RISK
open ↗VulnCheck XDB
info-leak
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection
85RISK
open ↗GitHub PoC
CVE-2026-45247 - Draft
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISK
open ↗GitHub PoC
HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then extract MinIO credentials from admin settings. Use CVE-2024-46987 path traversal to steal an SSH private key, crack its passphrase, and escalate to root by abusing sudo permissions on facter via GTFOBins.
Arbitrary path traversal in Camaleon CMS
61RISK
open ↗GitHub PoC
rootdirective-sec/CVE-2026-34234-Lab
CtrlPanel: Unauthenticated RCE using installer script
48RISK
open ↗GitHub PoC
Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload
48RISK
open ↗GitHub PoC★ 13
Attack surface in the real-world environment of CVE-2026-41096
Windows DNS Client Remote Code Execution Vulnerability
48RISK
open ↗GitHub PoC
CVE-2026-5076 — ARMember Premium <= 7.3.1 Insecure Password Reset Mechanism → Full Admin Account Takeover | Proof of Concept
ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.