Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,305GitHub PoC 15,197VulnCheck XDB 8,932Nuclei 4,379Metasploit 3,493✓ verified onlyrecentpopularrisk
79,781 exploits
VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗VulnCheck XDB
initial-access
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open ↗GitHub PoC
Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.
Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri
41RISK
open ↗VulnCheck XDB
initial-access
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
48RISK
open ↗GitHub PoC★ 1
Use cve-2026-36425 killer edr,360 can killer
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RISK
open ↗VulnCheck XDB
initial-access
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RISK
open ↗VulnCheck XDB
initial-access
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RISK
open ↗VulnCheck XDB
client-side
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RISK
open ↗GitHub PoC
CVE-2026-17532 Docker Lab.
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
48RISK
open ↗VulnCheck XDB
initial-access
TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet
23RISK
open ↗GitHub PoC★ 2
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
78RISK
open ↗GitHub PoC★ 2
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.
Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection
48RISK
open ↗GitHub PoC★ 13
This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC★ 4
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open ↗Exploit-DB
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISK
open ↗GitHub PoC★ 1
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process
Sandbox escape in the DOM: Navigation component
48RISK
open ↗GitHub PoC
Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
TP-Link Archer BE800 V1 — VPN Key Injection RCE
Command Injection Vulnerability in VPN connection of Archer BE800
41RISK
open ↗GitHub PoC★ 34
CVE 1-day in http.sys
Windows HTTP.sys Elevation of Privilege Vulnerability
41RISK
open ↗VulnCheck XDB
remote-with-credentials
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.