Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,955cataloged exploits
36,205CVEs with public exploitation
24,695lab-tested
14,978 exploits
GitHub PoC
CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.
CVE-2026-67595CRITICAL01 Aug 2026
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
48RISK
open
GitHub PoC
Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output to escape the intended directory and overwrite a preexisting file.
CVE-2026-14361MEDIUM01 Aug 2026
Consul-template is vulnerable to path redirection in writeToFile through symlink attack
33RISK
open
GitHub PoC1
mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
CVE-2026-64531HIGH31 Jul 2026
net: openvswitch: reject oversized nested action attrs
41RISK
open
GitHub PoC
Unauthenticated RCE in DBGate <= 7.1.8
CVE-2026-47668CRITICAL31 Jul 2026
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
63RISK
open
GitHub PoC1
This is N-day patch we releasing by testing our model capabilities
CVE-2026-16723CRITICAL31 Jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
Authenticated Blind OS Command Injection in ClearOS
CVE-2026-67599HIGH31 Jul 2026
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
41RISK
open
GitHub PoC4
GhostLock (CVE-2026-43499) exploit for POCO F3 GT (aresin) — MediaTek Dimensity 1200, Linux 4.14.186 ARM64 kernel privilege escalation via futex PI chain manipulation
CVE-2026-43499HIGH31 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC10
GhostLock (CVE-2026-43499) kernel exploit for Poco M6 Pro (emerald) with locked bootloader
CVE-2026-43499HIGH31 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers
CVE-2026-63563MEDIUM31 Jul 2026
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
33RISK
open
GitHub PoC
CVE-2026-8337 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS that affects the Survey feature. Unlike CVE-2026-8347 (which involved Express associations), this vulnerability allows an unauthenticated attacker to participate in a restricted/private survey under specific site configurations.
CVE-2026-8337MEDIUM31 Jul 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
33RISK
open
GitHub PoC4
A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. The CA can be coerced into authenticating back to attacker-controlled infrastructure and then issuing a certificate that impersonates a Domain Controller.
CVE-2026-54121HIGH31 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2022-40684CRITICALunder attackransomware31 Jul 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2018-13379CRITICALunder attackransomware31 Jul 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC3
LuZe0y/pd2425-cve-2026-43499-config
CVE-2026-43499HIGH31 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC2
CVE-2026-66066 + File Read, RCE, Scanner, Lab
CVE-2026-66066CRITICAL31 Jul 2026
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open
GitHub PoC1
Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.
CVE-2024-23897CRITICALunder attackransomware31 Jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
CVE-2026-8347LOW31 Jul 2026
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
28RISK
open
GitHub PoC
Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection engineering, threat hunting, incident response, and Kubernetes security implications.
CVE-2026-43284HIGH31 Jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
Hunt-Benito/pgadmin-ai-assistant-sql-injection-cve-2026-17351-lexer-differential-bypass
CVE-2026-17351CRITICAL31 Jul 2026
pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)
48RISK
open
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2022-40684CRITICALunder attackransomware31 Jul 2026
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open
GitHub PoC
This is the compiled version. This is not my program though. This is only for directly downloading the compiled version in labs where there is no gcc
CVE-2026-43284HIGH31 Jul 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2020-3952CRITICALunder attack31 Jul 2026
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open
GitHub PoC1
CVE-2026-54121(CertiGhost) without MachineAccountQuota POC
CVE-2026-54121HIGH31 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2018-13379CRITICALunder attackransomware31 Jul 2026
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open
GitHub PoC
KunalKhandelwal-dev/cve-2021-41773-lab
CVE-2021-41773HIGHunder attackransomware30 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC2
Security research tool for FortiWeb CVE-2025-64446 vulnerability. Automated exploitation framework with advanced logging, real-time metrics, proxy debugging, and professional reporting. Includes retry logic, multi-threading, and configurable settings. For authorized security testing only. CVSS 9.8 Critical.
CVE-2025-64446CRITICALunder attack30 Jul 2026
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
100RISK
open
GitHub PoC
HeltonPojo/CVE-2025-32432
CVE-2025-32432CRITICALunder attack30 Jul 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC
nawalacheker1/CVE-2026-46331
CVE-2026-46331HIGH30 Jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
CVE-2026-57827CRITICAL30 Jul 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISK
open
GitHub PoC
DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2
CVE-2026-61424CRITICAL30 Jul 2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.