Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
79,781 exploits
GitHub PoC
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.
CVE-2026-72530CRITICALunder attack25 Aug 2026
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
78RISK
open
GitHub PoC
Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.
CVE-2026-18963CRITICAL25 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALunder attackransomware25 Aug 2026
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC13
This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).
CVE-2026-18963CRITICAL25 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC4
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
CVE-2026-32475CRITICAL25 Aug 2026
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open
GitHub PoC2
CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).
CVE-2026-15469HIGH25 Aug 2026
Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800
41RISK
open
Exploit-DB
CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
CVE-2026-42167HIGHremotemultiple25 Aug 2026
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th
56RISK
open
GitHub PoC
CVE-2020-1472
CVE-2020-1472MEDIUMunder attackransomware25 Aug 2026
Netlogon Elevation of Privilege Vulnerability
100RISK
open
GitHub PoC88
CVE-2026-75604 Next.js Windows RCE poc
CVE-2026-75604CRITICAL25 Aug 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
48RISK
open
GitHub PoC
Patch: Privilege escalation via web UI (Cisco IOS XE)
CVE-2026-19843HIGH24 Aug 2026
389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
41RISK
open
GitHub PoC
SIMPLE EXPOIT FOR CVE-2025-55182 FOR RCE , COMMAND INJECTIONS AND OTHER VULNERABILITIES
CVE-2025-55182CRITICALunder attackransomware24 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
h00die/POC-CVE-2026-19626
CVE-2026-19626CRITICAL24 Aug 2026
Remote Code Execution
63RISK
open
GitHub PoC
Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.
CVE-2026-68820HIGHunder attack24 Aug 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
Reproducer for CVE-2026-63621 (Apache Camel camel-knative structured CloudEvent header injection) — Camel Spring Boot + Camel Quarkus
CVE-2026-63621MEDIUM24 Aug 2026
Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
33RISK
open
GitHub PoC
Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)
CVE-2026-63039CRITICAL24 Aug 2026
Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
48RISK
open
GitHub PoC
Patch: OGNL injection (Apache Struts)
CVE-2026-10520CRITICAL24 Aug 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
GitHub PoC
Patch: SSRF leading to RCE (Microsoft Exchange Server)
CVE-2026-15502MEDIUM24 Aug 2026
AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
33RISK
open
GitHub PoC
Patch: Authentication bypass (VMware vCenter)
CVE-2026-11553HIGH24 Aug 2026
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
41RISK
open
VulnCheck XDB
denial-of-service
CVE-2025-20333CRITICALunder attack24 Aug 2026
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu
100RISK
open
GitHub PoC1
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement, via mojo-port send-path injection from a compromised content process
CVE-2026-74939HIGH24 Aug 2026
Privilege escalation in the DOM: Navigation component
41RISK
open
GitHub PoC
Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.
CVE-2019-0708CRITICALunder attackransomware24 Aug 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
CVE-2026-73570 PoC
CVE-2026-73570HIGHunder attack24 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open
GitHub PoC
CVE-2025-48595 Android Framework Integer Overflow PoC - 优化版
CVE-2025-48595HIGHunder attack24 Aug 2026
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISK
open
GitHub PoC19
CVE-2026-18963
CVE-2026-18963CRITICAL24 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
Patch: Command injection in GlobalProtect (Palo Alto PAN-OS)
CVE-2026-14290MEDIUM24 Aug 2026
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
33RISK
open
GitHub PoC
Patch: Remote code execution in SPL parsing (Splunk Enterprise)
CVE-2026-28001CRITICAL24 Aug 2026
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-10520CRITICAL24 Aug 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
CVE-2026-12087CRITICAL24 Aug 2026
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-18963CRITICAL24 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware24 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
previouspage 14 / 2,660next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.