Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
79,386 exploits
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware15 Aug 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut
CVE-2026-6440MEDIUM15 Aug 2026
GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-71362CRITICAL15 Aug 2026
Adobe Commerce | Incorrect Authorization (CWE-863)
68RISK
open
GitHub PoC
DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation
CVE-2024-4577CRITICALunder attackransomware15 Aug 2026
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
ghostpels/CVE-2026-13610
CVE-2026-13610HIGH15 Aug 2026
KiviCare < 4.5.2 - Unauthenticated Privilege Escalation via Registration
41RISK
open
GitHub PoC
PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.
CVE-2026-9090CRITICAL15 Aug 2026
CVE-2026-9090
48RISK
open
GitHub PoC
uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.
CVE-2026-9147HIGH15 Aug 2026
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
41RISK
open
GitHub PoC
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.
CVE-2026-17544HIGH15 Aug 2026
Out-of-bounds write in bccomp() via crafted operand and scale
41RISK
open
GitHub PoC
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.
CVE-2026-47103CRITICAL15 Aug 2026
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
48RISK
open
GitHub PoC
Responsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11
CVE-2026-8793MEDIUM15 Aug 2026
PaperCut NG/MF: Insufficient brute-force protection
33RISK
open
GitHub PoC
Hunt-Benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork
CVE-2026-73678CRITICAL15 Aug 2026
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
48RISK
open
GitHub PoC
S2-072(CVE-2026-73633)poc
CVE-2026-73633HIGH15 Aug 2026
Apache Struts: Unbounded read of a JSON request body
41RISK
open
GitHub PoC489
CVE-2026-9830 Proof of Concept
CVE-2026-9830HIGH15 Aug 2026
BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug
41RISK
open
GitHub PoC
Username Enumeration via Authentication Timing Side-Channel in PaperCut NG
CVE-2026-8794MEDIUM15 Aug 2026
PaperCut NG/MF: User enumeration via timing attack
33RISK
open
GitHub PoC4
One-command Docker lab reproducing CVE-2026-71362 (Adobe Commerce / Magento Open Source customer-session identity-switch account takeover, APSB26-92, CVSS 9.1) with a PoC and an A/B/A official-patch negative control. For authorized security research and education.
CVE-2026-71362CRITICAL15 Aug 2026
Adobe Commerce | Incorrect Authorization (CWE-863)
68RISK
open
GitHub PoC
OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True
CVE-2026-47117CRITICAL15 Aug 2026
OpenMed < 1.5.2 Remote Code Execution via PII Model Loading
48RISK
open
GitHub PoC1
This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (`afd.sys`).
CVE-2026-68820HIGHunder attack15 Aug 2026
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC4
CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection
CVE-2026-72898CRITICALunder attack15 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC2
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.
CVE-2026-43499HIGH15 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Full root in kernel domain with selinux permissive **MOVED TO THIS REPO https://github.com/CamsShaft/IonStack-S22 WILL DELETE THIS ONE SOON**
CVE-2026-43499HIGH15 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-58231 Detection & Confirmation Script
CVE-2026-58231CRITICAL15 Aug 2026
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
48RISK
open
GitHub PoC
CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)
CVE-2026-43499HIGH15 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC2
SambaCry Explanation and Exploitation Demo with POC
CVE-2017-7494CRITICALunder attackransomware15 Aug 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
GitHub PoC
CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini memungkinkan penyerang untuk menyisipkan kode JavaScript berbahaya ke halaman login WordPress (/wp-login.php) tanpa perlu autentikasi terlebih dahulu.
CVE-2026-64638HIGH15 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
AI Infrastructure Vulnerability Research. CVE-2026-78906: Prompt injection and memory exfiltration in OpenAI's ChatGPT API.
CVE-2026-78906HIGH15 Aug 2026
Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
41RISK
open
GitHub PoC1
CVE-2026-72898-Metabase-SQLi-Fix
CVE-2026-72898CRITICALunder attack15 Aug 2026
Metabase SQL injection via password reset endpoint
100RISK
open
GitHub PoC1
This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here.
CVE-2026-43499HIGH14 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Mohaimenul370/Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows
CVE-2019-0708CRITICALunder attackransomware14 Aug 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
jeffmarlonmandela/CVE-2021-4034-PwnKit
CVE-2021-4034HIGHunder attackransomware14 Aug 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware14 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
previouspage 18 / 2,647next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.