Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,521GitHub PoC 15,321VulnCheck XDB 8,970Nuclei 4,394Metasploit 3,502✓ verified onlyrecentpopularrisk
80,184 exploits
GitHub PoC
NullByte8080/CVE-2026-36226
Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensit
33RISK
open ↗GitHub PoC
Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model Runner MLX / SGLANG / VLLM inference backend.
Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
41RISK
open ↗GitHub PoC★ 2
Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open ↗GitHub PoC
This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by using any incorrect password in a Basic Authentication header. Attackers could abuse this flaw to create a new administrator account without prior authentication.
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open ↗GitHub PoC★ 1
PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab, empirical address discovery, OOB-verified offset sweep. Original disclosure by depthfirst.
NGINX ngx_http_rewrite_module vulnerability
60RISK
open ↗GitHub PoC★ 2
Safely detect whether a PAN-OS target is vulnerable to CVE-2026-0265.
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RISK
open ↗GitHub PoC
Portable Python PoC for CVE-2026-31431 (Copy Fail)
crypto: algif_aead - Revert to operating out-of-place
100RISK
open ↗GitHub PoC
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open ↗GitHub PoC
CVE-2026-34926
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker t
68RISK
open ↗GitHub PoC★ 3
CVE-2026-20182 PoC - Cisco Catalyst SD-WAN Controller / Manager Authentication Bypass (CVSS 10.0)
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open ↗GitHub PoC★ 2
A safe read-only Linux check for CVE-2026-31431 / Copy Fail without running exploit code.
crypto: algif_aead - Revert to operating out-of-place
100RISK
open ↗GitHub PoC
CVE-2026-31431 / Copy Fail Linux kernel vulnerability checker - algif_aead attack path detection
crypto: algif_aead - Revert to operating out-of-place
100RISK
open ↗GitHub PoC
Portable Python PoC for CVE-2026-31431 (Copy Fail)
crypto: algif_aead - Revert to operating out-of-place
100RISK
open ↗GitHub PoC
CVE-2024-6387 POC (Currently being edited)
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open ↗GitHub PoC
NullByte8080/CVE-2026-36228
Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu
41RISK
open ↗GitHub PoC
Critical WIC bug (9.8): uninitialized JPEG encode pointers in WindowsCodecs.dll — triggers on 12/16-bit re-encode, not casual preview.
Windows Graphics Component Remote Code Execution Vulnerability
48RISK
open ↗GitHub PoC
Scanner: CVE-2026-41091/45498 Microsoft Defender LPE/DoS — Python scanner for Windows Defender privilege escalation (CISA KEV)
Microsoft Defender Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC
NullByte8080/CVE-2026-36227
Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and e
33RISK
open ↗GitHub PoC★ 1
Python exploit toolkit for WordPress Crop Image RCE — CVE-2019-8942 & CVE-2019-8943
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open ↗GitHub PoC
A Go implementation of PinTheft (CVE-2026-43494)
net/rds: reset op_nents when zerocopy page pin fails
41RISK
open ↗GitHub PoC
logis11/CVE-2025-55423-analysis-and-reproduction
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr
48RISK
open ↗VulnCheck XDB
initial-access
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open ↗VulnCheck XDB
initial-access
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open ↗GitHub PoC
BastianXploited/CVE-2026-8181
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open ↗VulnCheck XDB
initial-access
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open ↗VulnCheck XDB
initial-access
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.