Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
14,946 exploits
GitHub PoC
Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.
CVE-2026-60137MEDIUMunder attack05 Aug 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC914
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
CVE-2026-63030CRITICALunder attack05 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
CVE-2026-33017 Langflow RCE PoC
CVE-2026-33017CRITICALunder attack05 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health probe configurations.
CVE-2026-43284HIGH05 Aug 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC4
learner330/fastjson-cve-2026-16723
CVE-2026-16723CRITICAL05 Aug 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
xuwu-xuwu/CVE-2026-68004
CVE-2026-68004CRITICAL05 Aug 2026
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP pub
48RISK
open
GitHub PoC
minwunn/wp2shell-CVE-2026-63030
CVE-2026-63030CRITICALunder attack05 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
CVE-2026-0092- Possible device lock controller bypass due to a missing permission check.
CVE-2026-0092CRITICAL05 Aug 2026
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead
48RISK
open
GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
CVE-2026-67689CRITICAL05 Aug 2026
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RISK
open
GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
CVE-2025-66390CRITICAL05 Aug 2026
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISK
open
GitHub PoC2
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC
CVE-2026-17532MEDIUM05 Aug 2026
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
48RISK
open
GitHub PoC1
CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.
CVE-2026-42533CRITICAL05 Aug 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC
ICS-Park Smart Park Management System v2.0
CVE-2026-67687HIGH05 Aug 2026
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RISK
open
GitHub PoC1
WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection
CVE-2026-63030CRITICALunder attack05 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
0xdak/CVE-2026-44024_exploit
CVE-2026-44024CRITICAL05 Aug 2026
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
48RISK
open
GitHub PoC
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version scheme. CVE-2026-58062 / CVE-2026-8763 / CVE-2026-59650 / CVE-2026-59638
CVE-2026-58062CRITICAL05 Aug 2026
Stapled OCSP response accepted without binding to the checked certificate
48RISK
open
GitHub PoC
lucastran05/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware05 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research
CVE-2025-32432CRITICALunder attack05 Aug 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC
Dungsocool/CVE-2023-6553
CVE-2023-6553CRITICAL05 Aug 2026
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
85RISK
open
GitHub PoC12
PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).
CVE-2026-15430MEDIUM05 Aug 2026
CVE-2026-15430
33RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open
CVE-2026-11111HIGH04 Aug 2026
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bound
41RISK
open
GitHub PoC1
Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architecture, professional reporting, screenshot capture, SQLite database, and 95%+ confidence detection. Author: Sudeepa Wanigarathna.
CVE-2021-4479004 Aug 2026
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RISK
open
GitHub PoC
0xdak/CVE-2026-59243_exploit
CVE-2026-59243CRITICAL04 Aug 2026
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11120-Command-Injection-via-Git-URL-in-CI-CD-Pipeline
CVE-2026-11120CRITICAL04 Aug 2026
Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a rem
48RISK
open
GitHub PoC2
CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434 | CI4 < 4.7.4
CVE-2026-63223CRITICAL04 Aug 2026
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form
CVE-2026-11113CRITICAL04 Aug 2026
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
48RISK
open
GitHub PoC
Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.
CVE-2026-17543HIGH04 Aug 2026
SQL injection in ext-pgsql via E'...' backslash breakout
41RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-11108-Integer-Overflow-in-Memory-Allocator-kmalloc-Sim-
CVE-2026-11108HIGH04 Aug 2026
Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perf
41RISK
open
GitHub PoC1
pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch
CVE-2026-17566CRITICAL04 Aug 2026
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
48RISK
open
GitHub PoC
George0Papasotiriou/CVE-2026-21020-Protobuf-Message-Parsing-Polymorphic-Deserialization-Vulnerability
CVE-2026-21020MEDIUM04 Aug 2026
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to tri
33RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.