Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,329cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,458Referência 22,721GitHub PoC 14,482VulnCheck XDB 8,829Nuclei 4,350Metasploit 3,489✓ verified onlyrecentpopularrisk
14,482 exploits
GitHub PoC
Poc CVE-2026-18080
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.8 - Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment
48RISK
open ↗GitHub PoC
PostGIS SQL Injection GeoTools
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
63RISK
open ↗GitHub PoC
sergiofigueras/cve-2026-46858
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM
48RISK
open ↗GitHub PoC
t3bik/CVE-2026-75898
RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
41RISK
open ↗GitHub PoC
WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RISK
open ↗GitHub PoC
Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.
Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri
41RISK
open ↗GitHub PoC★ 1
POC pre-auth RCE on Sharepoint chain
Microsoft SharePoint Server Remote Code Execution Vulnerability
41RISK
open ↗GitHub PoC
ksotaria1337/-CVE-2026-48907-
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open ↗GitHub PoC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
48RISK
open ↗GitHub PoC
Exploit for CVE-2026-18963 by BlackHatExploitation
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
PoC, Dockerfile playground and root cause from patch diff analysis.
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
48RISK
open ↗GitHub PoC★ 2
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
WordPress Elementor Pro plugin <= 4.2.1 - Arbitrary File Upload vulnerability
63RISK
open ↗GitHub PoC
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗GitHub PoC★ 13
This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC★ 2
CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).
Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800
41RISK
open ↗GitHub PoC★ 2
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.
Adminer before 5.4.3 Remote Code Execution via MSSQL PDO DSN Injection
48RISK
open ↗GitHub PoC★ 1
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process
Sandbox escape in the DOM: Navigation component
48RISK
open ↗GitHub PoC★ 2
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RISK
open ↗GitHub PoC
CVE-2026-17532 Docker Lab.
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting
48RISK
open ↗GitHub PoC
Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC★ 1
Use cve-2026-36425 killer edr,360 can killer
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user
33RISK
open ↗GitHub PoC
TP-Link Archer BE800 V1 — VPN Key Injection RCE
Command Injection Vulnerability in VPN connection of Archer BE800
41RISK
open ↗GitHub PoC
CVE-2026-68820 — Mass Exploit Framework Edition.
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
71RISK
open ↗GitHub PoC
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
78RISK
open ↗GitHub PoC
Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)
Apache Ranger: OS Command Injection via Username in UnixUserGroupBuilder
48RISK
open ↗GitHub PoC
Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)
Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
48RISK
open ↗GitHub PoC
Reproducer for CVE-2026-59230 (Apache Camel camel-mail MimeMultipart headersInline header injection) — Camel Spring Boot + Camel Quarkus
Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
33RISK
open ↗GitHub PoC
Patch: Authentication bypass (VMware vCenter)
Tenda HG7HG9/HG10 formPPPEdit stack-based overflow
41RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.