Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
79,781 exploits
GitHub PoC
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALunder attack28 Aug 2026
Unauthenticated Command Injection
100RISK
open
GitHub PoC
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
CVE-2025-57819CRITICALunder attack27 Aug 2026
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open
GitHub PoC
Gvln-S/CVE-2011-2523
CVE-2011-252327 Aug 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC1
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.
CVE-2026-75604CRITICAL27 Aug 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISK
open
GitHub PoC
SneakyNachos/CVE-2026-74936-gc-potato
CVE-2026-74936CRITICAL27 Aug 2026
Use-after-free in the JavaScript: WebAssembly component
48RISK
open
GitHub PoC1
CVE-2026-18431 - Draft or TODO
CVE-2026-18431CRITICAL27 Aug 2026
Avada <= 7.16 and Fusion Builder <= 3.16 - Unauthenticated Remote Code Execution via Arbitrary File Write
48RISK
open
GitHub PoC
CVE-2015-5287
CVE-2015-5287HIGHunder attack27 Aug 2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISK
open
GitHub PoC
Hunt-Benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass
CVE-2026-67602CRITICAL27 Aug 2026
phpIPAM < 1.8.2 Authentication Bypass via REST API Object Cache
48RISK
open
GitHub PoC
CVE-2026-55040
CVE-2026-55040CRITICALunder attack27 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALunder attack27 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL27 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
CVE-2026-77542CRITICAL27 Aug 2026
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
48RISK
open
VulnCheck XDB
initial-access
CVE-2021-27876HIGHunder attackransomware27 Aug 2026
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open
VulnCheck XDB
initial-access
CVE-2020-14750CRITICALunder attack27 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-21962CRITICALunder attack27 Aug 2026
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo
90RISK
open
GitHub PoC22
Metabase SQLi
CVE-2026-72898CRITICALunder attack27 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-72898CRITICALunder attack27 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
VulnCheck XDB
local
CVE-2015-5287HIGHunder attack27 Aug 2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RISK
open
VulnCheck XDB
initial-access
CVE-2026-19478CRITICAL27 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC3
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
CVE-2026-18963CRITICAL27 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
CVE-2026-20303CRITICAL27 Aug 2026
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
48RISK
open
GitHub PoC1
sahmsec/CVE-2026-32475
CVE-2026-32475CRITICAL27 Aug 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open
GitHub PoC4
GitLab Code injection
CVE-2026-19478CRITICAL27 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
CVE-2026-55040CRITICALunder attack27 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
CVE-2026-47851HIGH27 Aug 2026
Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader
21RISK
open
GitHub PoC
CVE-2015-3246
CVE-2015-3246MEDIUMunder attack27 Aug 2026
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RISK
open
GitHub PoC
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
CVE-2020-14882CRITICALunder attack27 Aug 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open
GitHub PoC
For educational purposes
CVE-2026-65351MEDIUM27 Aug 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS
33RISK
open
Metasploit600
PaperCut NG/MF Unauthenticated RCE (CVE-2026-81578 + CVE-2026-82078)
CVE-2026-82078CRITICALunder attack27 Aug 2026
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector
93RISK
open
Metasploit600
PaperCut NG/MF Unauthenticated RCE (CVE-2026-81578 + CVE-2026-82078)
CVE-2026-81578HIGHunder attack27 Aug 2026
PaperCut MF/NG: Authentication Bypass
86RISK
open
previouspage 11 / 2,660next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.