Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
80,184 exploits
GitHub PoC
yangh-beep/CVE-2026-31431-C
CVE-2026-31431HIGHunder attack21 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC1
More portable POC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux
CVE-2026-31431HIGHunder attack21 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)
CVE-2026-33829MEDIUM21 May 2026
Windows Snipping Tool Spoofing Vulnerability
33RISK
open
GitHub PoC2
CVE-2026-9082 | SA-CORE-2026-004
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC1
CVE-2026-5118-exp_wordpress_Divi Form Builder
CVE-2026-5118CRITICAL21 May 2026
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
48RISK
open
GitHub PoC
CVE-2026-45829
CVE-2026-45829CRITICAL21 May 2026
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RISK
open
GitHub PoC
A Go implementation of dirtydecrypt (CVE-2026-31635)
CVE-2026-31635HIGH21 May 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISK
open
GitHub PoC24
Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites.
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC1
Scanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.
CVE-2024-6387HIGH21 May 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service in the kernel.
CVE-2026-38763MEDIUM21 May 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the
33RISK
open
GitHub PoC1
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
CVE-2026-38764HIGH21 May 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RISK
open
VulnCheck XDB
initial-access
CVE-2021-41773HIGHunder attackransomware21 May 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autofstx.exe` from the offline WinRE image's `BootExecute` value and refreshes WinRE registration so BitLocker trust is reestablished.
CVE-2026-45585MEDIUM21 May 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
GitHub PoC2
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload → RCE
CVE-2026-4885CRITICAL21 May 2026
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload
48RISK
open
VulnCheck XDB
local
CVE-2026-31635HIGH21 May 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISK
open
GitHub PoC
「🪶」PoC (Proof of concept) of Path traversal + RCE in Apache HTTP Server 2.4.49
CVE-2021-41773HIGHunder attackransomware21 May 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via a kernel mode driver.
CVE-2026-38766HIGH21 May 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1
41RISK
open
GitHub PoC
CVE-2026-46680 exploit
CVE-2026-46680HIGH21 May 2026
containerd user ID handling bypass allows runAsNonRoot evasion
41RISK
open
GitHub PoC2
An issue in Unistal Systems Pvt. Ltd. Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
CVE-2026-38765HIGH21 May 2026
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
41RISK
open
Metasploit300
PAN-OS GlobalProtect CAS CVE-2026-0265 Vulnerability Checker
CVE-2026-0265HIGH21 May 2026
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
56RISK
open
GitHub PoC22
CVE-2026-45250: FreeBSD 14.4 setcred kernel buffer overflow (LPE)
CVE-2026-45250HIGH21 May 2026
Stack buffer overflow via setcred(2)
41RISK
open
Metasploit300
Concrete CMS Unauthenticated File Usage Disclosure
CVE-2026-6826MEDIUM21 May 2026
Concrete 9.5.0 and below has file usage disclosure via missing permission check in Usage controller
28RISK
open
GitHub PoC1
PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
Exploit-DB
FUXA 1.2.9 - RCE
CVE-2026-25895CRITICALwebappsmultiple21 May 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
68RISK
open
Metasploit300
Drupal Core PostgreSQL EntityQuery SQL Injection
CVE-2026-9082CRITICALunder attack20 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
Maxime288/Fragnesia-CVE-2026-46300
CVE-2026-46300HIGH20 May 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open
GitHub PoC
Se realizó una evaluación de vulnerabilidades sobre una máquina virtual con Kali Linux utilizando un script detector para la vulnerabilidad Dirty Frag, asociada a las CVE-2026-43284 y CVE-2026-43500. Posteriormente se ejecutó un Proof of Concept (PoC) público escrito en lenguaje C para validar la posibilidad de realizar una escalada local
CVE-2026-43284HIGH20 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
A Go implementation of dirtyfrag (CVE-2026-43284 / CVE-2026-43500)
CVE-2026-43284HIGH20 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
fevar54/FULL-ANALYSIS---CVE-2026-45829-ChromaDB-
CVE-2026-45829CRITICAL20 May 2026
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RISK
open
GitHub PoC
A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions
CVE-2026-45585MEDIUM20 May 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
previouspage 122 / 2,673next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.