Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,305GitHub PoC 15,197VulnCheck XDB 8,932Nuclei 4,379Metasploit 3,493✓ verified onlyrecentpopularrisk
79,781 exploits
GitHub PoC
xAL6/cve-2026-64638-banner-poc
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malici
68RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC★ 19
CVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC★ 2
T0w0T/POC-CVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
minh3102011/CVE-2026-18963_analyst
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)
Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
48RISK
open ↗GitHub PoC
Patch: SSRF leading to RCE (Microsoft Exchange Server)
AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
33RISK
open ↗GitHub PoC
CVE-2026-73570 PoC
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
98RISK
open ↗GitHub PoC
Patch: Privilege escalation via web UI (Cisco IOS XE)
389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor
41RISK
open ↗GitHub PoC
Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
48RISK
open ↗GitHub PoC
Reproducer for CVE-2026-59230 (Apache Camel camel-mail MimeMultipart headersInline header injection) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
33RISK
open ↗GitHub PoC
SIMPLE EXPOIT FOR CVE-2025-55182 FOR RCE , COMMAND INJECTIONS AND OTHER VULNERABILITIES
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
Reproducer for CVE-2026-63621 (Apache Camel camel-knative structured CloudEvent header injection) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
33RISK
open ↗GitHub PoC
CVE-2025-48595 Android Framework Integer Overflow PoC - 优化版
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISK
open ↗GitHub PoC★ 1
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement, via mojo-port send-path injection from a compromised content process
Privilege escalation in the DOM: Navigation component
41RISK
open ↗GitHub PoC★ 2
CVE-2026-77806漏洞检测代码
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RISK
open ↗GitHub PoC★ 1
Legendile7/CVE-2026-78122-POC
docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
41RISK
open ↗GitHub PoC
IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0
41RISK
open ↗GitHub PoC
CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISK
open ↗GitHub PoC
Professional PHPMyAdmin 5.0.0 SQL Injection (CVE-2020-5504) exploitation framework with automated database enumeration, table extraction, and data dumping capabilities. Features blind injection, proxy support, JSON output, and comprehensive error handling for authorized penetration testing and security research. Author: Sudeepa Wanigarathna
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISK
open ↗GitHub PoC★ 1
PoC exploit chain for CVE-2026-15718: SpiderMonkey wasm baseline compiler array.fill missing-sync -> invalid pointer -> addrOf/fakeobj -> arbitrary R/W -> RCE
Invalid pointer in the JavaScript: WebAssembly component
33RISK
open ↗GitHub PoC
From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open ↗GitHub PoC★ 4
Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2, deterministic oracle.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RISK
open ↗GitHub PoC
chessalekin/cve-2026-9198_exploit
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open ↗GitHub PoC
Password-Protected Category Bypass via JSON Format in JoomGallery
Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0
33RISK
open ↗GitHub PoC
Exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 — a hands-on pentesting lab writeup covering recon, exploitation, and remediation.
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗GitHub PoC★ 1
Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.