Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
79,781 exploits
GitHub PoC3
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
CVE-2026-18963CRITICAL27 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
CVE-2026-55040CRITICALunder attack27 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC
SneakyNachos/CVE-2026-74936-gc-potato
CVE-2026-74936CRITICAL27 Aug 2026
Use-after-free in the JavaScript: WebAssembly component
48RISK
open
GitHub PoC4
Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)
CVE-2026-73570HIGHunder attack26 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
GitHub PoC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
CVE-2026-19632CRITICAL26 Aug 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RISK
open
GitHub PoC1
POC pre-auth RCE on Sharepoint chain
CVE-2026-63520HIGH26 Aug 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RISK
open
GitHub PoC1
CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing
CVE-2026-75604CRITICAL26 Aug 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISK
open
GitHub PoC
Poc CVE-2026-18080
CVE-2026-18080CRITICAL26 Aug 2026
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
48RISK
open
GitHub PoC2
CVE-2026-19632 - TranslatePress One-Day PoC
CVE-2026-19632CRITICAL26 Aug 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RISK
open
VulnCheck XDB
info-leak
CVE-2026-72898CRITICALunder attack26 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-73570HIGHunder attack26 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
GitHub PoC
ksotaria1337/-CVE-2026-48907-
CVE-2026-48907CRITICALunder attack26 Aug 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-19632CRITICAL26 Aug 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-32475CRITICAL26 Aug 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL26 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
zenzue/CVE-2026-55040
CVE-2026-55040CRITICALunder attack26 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-55040CRITICALunder attack26 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC
sergiofigueras/cve-2026-46858
CVE-2026-46858CRITICAL26 Aug 2026
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-63520HIGH26 Aug 2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RISK
open
VulnCheck XDB
local
CVE-2026-36425MEDIUM26 Aug 2026
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RISK
open
GitHub PoC
Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.
CVE-2026-79266HIGH26 Aug 2026
Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-73570HIGHunder attack26 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
GitHub PoC
Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)
CVE-2026-72898CRITICALunder attack26 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC
CVE-2026-63072
CVE-2026-63072HIGH26 Aug 2026
Heap Buffer Overflow in CMS Key Unwrapping
41RISK
open
GitHub PoC
CVE-2026-19912, CVE-2026-19913, CVE-2026-19914
CVE-2026-19912CRITICAL26 Aug 2026
CVE-2026-19912
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-48907CRITICALunder attack26 Aug 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
VulnCheck XDB
local
CVE-2016-5195HIGHunder attack26 Aug 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
t3bik/CVE-2026-75898
CVE-2026-75898HIGH26 Aug 2026
RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-19632CRITICAL26 Aug 2026
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
63RISK
open
VulnCheck XDB
initial-access
CVE-2026-73570HIGHunder attack26 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
previouspage 12 / 2,660next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.