Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
80,183 exploits
GitHub PoC
muslimbek-0x/CVE-2026-48030
CVE-2026-48030CRITICAL28 May 2026
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)
63RISK
open
GitHub PoC
CVE-2023-26083-Mali-InfoLeak-PoC
CVE-2023-26083LOWunder attack28 May 2026
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost
58RISK
open
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL28 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)
CVE-2007-244728 May 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
initial-access
CVE-2026-31431HIGHunder attack28 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC2
W5M1n9/NGINX-ngx_http_rewrite_module-heap-buffer-overflow-CVE-2026-9256
CVE-2026-9256CRITICAL28 May 2026
NGINX ngx_http_rewrite_module vulnerability
53RISK
open
GitHub PoC1
A x86_64 ASM implementation of PinTheft (CVE-2026-43494)
CVE-2026-43494HIGH28 May 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISK
open
GitHub PoC1
funixone/EXPLOIT-CVE-2026-8832
CVE-2026-8832HIGH28 May 2026
WPCode <= 2.3.5 - Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost
41RISK
open
GitHub PoC10
Public advisory for CVE-2025-65640: Stored XSS vulnerability in Globe Document Intelligence.
CVE-2025-65640MEDIUM28 May 2026
Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.
33RISK
open
GitHub PoC
rootdirective-sec/CVE-2026-47100-Analysis-Lab
CVE-2026-47100HIGH28 May 2026
Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX
41RISK
open
GitHub PoC3
3nou9h/CVE-2026-9256-Poc
CVE-2026-9256CRITICAL28 May 2026
NGINX ngx_http_rewrite_module vulnerability
53RISK
open
GitHub PoC1
Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI
CVE-2026-48710MEDIUMunder attack28 May 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
90RISK
open
GitHub PoC
quantumworld-dpdns-io/CVE-2026-42945
CVE-2026-42945CRITICAL28 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
EXPLOIT CVE-2026-8832
CVE-2026-8832HIGH28 May 2026
WPCode <= 2.3.5 - Authenticated (Author+) Remote Code Execution via CPT Capability Bypass via XML-RPC wp.newPost
41RISK
open
GitHub PoC
CVE-2026-8380
CVE-2026-8380MEDIUM28 May 2026
Frontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post Deletion
33RISK
open
GitHub PoC
SSRF Discovered in Mercator
CVE-2026-49345MEDIUM27 May 2026
Mercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)
13RISK
open
GitHub PoC
CVE-2021-3560 — Polkit privilege escalation exploit via accounts-daemon D-Bus race condition
CVE-2021-3560HIGHunder attack27 May 2026
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open
GitHub PoC1
Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710
CVE-2026-48710MEDIUMunder attack27 May 2026
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
90RISK
open
GitHub PoC1
CVE-2026-45659
CVE-2026-45659HIGHunder attackransomware27 May 2026
Microsoft SharePoint Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
This exploit is based on CVE-2019-6340 and was built upon the original exploit by leonjza and the Metasploit module, extending it can be executed multiple times against the same target without waiting for cache expiration.
CVE-2019-6340HIGHunder attack27 May 2026
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC
hadhub/CVE-2026-49344-Mercator-JSON-DSL
CVE-2026-49344HIGH27 May 2026
Mercator has a Personal Identifiable Information Leak from Query Executor feature
21RISK
open
Exploit-DB
MeiG Smart FORGE_SLT711 - OS Command Injection
CVE-2026-36356CRITICALhardwarelinux27 May 2026
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica
53RISK
open
VulnCheck XDB
info-leak
CVE-2026-26980CRITICAL27 May 2026
Ghost has a SQL Injection in its Content API
85RISK
open
Exploit-DB
Casdoor 3.54.1 - Arbitrary File Write via Path Traversal
CVE-2026-6815MEDIUMwebappsgo27 May 2026
CVE-2026-6815
33RISK
open
GitHub PoC
Passive checker for CVE-2026-9082 / SA-CORE-2026-004 (Drupal core SQL injection, PostgreSQL)
CVE-2026-9082CRITICALunder attack27 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-9082CRITICALunder attack27 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-54123CRITICAL27 May 2026
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open
GitHub PoC
lwd3c/CVE-2026-47342
CVE-2026-47342HIGH27 May 2026
Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
21RISK
open
GitHub PoC2
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool against systems without explicit written permission is illegal. The developers are not responsible for any misuse or damage caused.
CVE-2026-41940CRITICALunder attackransomware27 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
this is a study about CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)
CVE-2021-3156HIGHunder attack27 May 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
previouspage 114 / 2,673next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.