Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,521GitHub PoC 15,321VulnCheck XDB 8,970Nuclei 4,394Metasploit 3,502✓ verified onlyrecentpopularrisk
80,184 exploits
GitHub PoC
this is a study about CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open ↗Exploit-DB
scramble - Remote Code Execution
Scramble: Remote code execution via evaluation of user-controlled input in validation rules
63RISK
open ↗VulnCheck XDB
local
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗GitHub PoC
This exploit is based on CVE-2019-6340 and was built upon the original exploit by leonjza and the Metasploit module, extending it can be executed multiple times against the same target without waiting for cache expiration.
Drupal core - Highly critical - Remote Code Execution
100RISK
open ↗GitHub PoC
SSRF Discovered in Mercator
Mercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)
13RISK
open ↗GitHub PoC
Lab 3: Supervisord XML-RPC Remote Code Execution (CVE-2017-11610) - Writeup and Exploit
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RISK
open ↗GitHub PoC
hadhub/CVE-2026-49344-Mercator-JSON-DSL
Mercator has a Personal Identifiable Information Leak from Query Executor feature
21RISK
open ↗GitHub PoC
CVE-2021-3560 — Polkit privilege escalation exploit via accounts-daemon D-Bus race condition
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗GitHub PoC
CVE-2026-5172: buffer overflow in extract_addresses() on crafted resource record PoC
CVE-2026-5172
41RISK
open ↗GitHub PoC★ 1
mein-0/cve-2026-0828
Kernel driver vulnerability in Safetica Endpoint Client
41RISK
open ↗GitHub PoC★ 1
Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
90RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗VulnCheck XDB
initial-access
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open ↗VulnCheck XDB
initial-access
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RISK
open ↗GitHub PoC
Generate the poc for CVE-2026-4893: broken EDNS Client Subnet validation.
CVE-2026-4893
33RISK
open ↗GitHub PoC
Dungsocool/CVE-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open ↗Exploit-DB
EspoCRM 9.3.3 - SSRF
EspoCRM has authenticated SSRF via internal-host validation bypass using alternative IPv4 notation
48RISK
open ↗GitHub PoC
CVE-2026-45659 Microsoft SharePoint Server Deserialization RCE.
Microsoft SharePoint Remote Code Execution Vulnerability
93RISK
open ↗GitHub PoC★ 3
Ghost Content API SQL Injection
Ghost has a SQL Injection in its Content API
85RISK
open ↗Exploit-DB
MeiG Smart FORGE_SLT711 - OS Command Injection
The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica
53RISK
open ↗GitHub PoC★ 2
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool against systems without explicit written permission is illegal. The developers are not responsible for any misuse or damage caused.
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open ↗Exploit-DB
cPanel - CRLF Injection
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open ↗GitHub PoC
CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.7 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
56RISK
open ↗GitHub PoC
CVE-2026-5364 is a CVSS 8.1 (High) Unauthenticated Arbitrary File Upload vulnerability in the Drag and Drop File Upload for Contact Form 7
Drag and Drop File Upload for Contact Form 7 <= 1.1.3 - Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.