Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,781cataloged exploits
36,771CVEs with public exploitation
24,695lab-tested
79,386 exploits
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware14 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
info-leak
CVE-2021-41773HIGHunder attackransomware14 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack14 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack14 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
local
CVE-2021-4034HIGHunder attackransomware14 Aug 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
CVE-2026-53365
CVE-2026-53365HIGH14 Aug 2026
vsock/virtio: fix zerocopy completion for multi-skb sends
41RISK
open
GitHub PoC
CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical)
CVE-2026-72550CRITICAL14 Aug 2026
Friendica Friendica - SQL Injection
48RISK
open
GitHub PoC1
This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here.
CVE-2026-43499HIGH14 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit time-based/boolean-based + exfiltracion sin comas en payload.
CVE-2026-52715CRITICAL14 Aug 2026
WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability
48RISK
open
GitHub PoC
CVE-2026-54433 Roundcube plain-text email stored XSS PoC
CVE-2026-54433HIGH14 Aug 2026
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plai
41RISK
open
GitHub PoC
PoC for RefluXFS
CVE-2026-64600HIGH14 Aug 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC61
CVE-2026-8452 PreAuth RCE
CVE-2026-8452HIGHunder attack14 Aug 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISK
open
GitHub PoC5
KSuRoot 2.2.0 — One-click KernelSU rooting based on CVE-2026-43499. Synced from Root-My-Galaxy v0.2.6 with custom payload (.so) import. Mod by hmascs
CVE-2026-43499HIGH14 Aug 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Kentox493/CVE-2026-46300_Fragnesia
CVE-2026-46300HIGH14 Aug 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open
GitHub PoC
KovachVL/CVE-2026-54356
CVE-2026-54356HIGH14 Aug 2026
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
41RISK
open
GitHub PoC
jeffmarlonmandela/CVE-2021-4034-PwnKit
CVE-2021-4034HIGHunder attackransomware14 Aug 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC
Mohaimenul370/Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows
CVE-2019-0708CRITICALunder attackransomware14 Aug 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
CVE-2021-41773 Exploit Lab
CVE-2021-41773HIGHunder attackransomware14 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
CS50's Introduction to Cybersecurity final project on React2Shell (CVE-2025-55182)
CVE-2025-55182CRITICALunder attackransomware14 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
Практические кейсы по информационной безопасности: развёртывание SIEM Wazuh и эксплуатация CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware13 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom Python PoC.
CVE-2021-41773HIGHunder attackransomware13 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Hunt-Benito/the-sanitizer-is-the-weapon-cve-2026-68749-cve-2026-68750-quadratic-dos-in-elixir-html-sanitize-ex
CVE-2026-68749HIGH13 Aug 2026
Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service
41RISK
open
GitHub PoC2
CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner
CVE-2026-56292CRITICAL13 Aug 2026
Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1
48RISK
open
GitHub PoC3
Original research and non-destructive PoC for an unauthenticated firmware update vulnerability with missing cryptographic firmware authentication in Netis NC63
CVE-2026-73673HIGH13 Aug 2026
Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication
41RISK
open
GitHub PoC
nullwhisper/CVE-2026-14840
CVE-2026-14840MEDIUM13 Aug 2026
YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing
33RISK
open
GitHub PoC1
GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)
CVE-2026-14282CRITICAL13 Aug 2026
GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field
48RISK
open
GitHub PoC
针对CVE-2026-41940漏洞的临时缓解措施
CVE-2026-41940CRITICALunder attackransomware13 Aug 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
josephfarah-ciso/CVE-2026-9999-exploit
CVE-2026-9999HIGH13 Aug 2026
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu
41RISK
open
GitHub PoC
The poc of CVE-2026-33017
CVE-2026-33017CRITICALunder attack13 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC1
CVE-2026-33017: Langflow Unauthenticated RCE PoC
CVE-2026-33017CRITICALunder attack13 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
previouspage 19 / 2,647next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.