Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
Microsoft SharePoint CVE-2026-50522
CVE-2026-50522CRITICALunder attack28 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVE-2026-54121HIGH28 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC4
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH28 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-14856 TastyIgniter v4.3.0
CVE-2026-14856MEDIUM28 Jul 2026
Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager
33RISK
open
GitHub PoC1
CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)
CVE-2026-8206CRITICAL28 Jul 2026
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
48RISK
open
GitHub PoC1
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution [RCE]
CVE-2026-9198CRITICALunder attack28 Jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC1
A PoC for CVE-2026-64725
CVE-2026-64725HIGH28 Jul 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS
41RISK
open
GitHub PoC3
cve-2026-61511
CVE-2026-61511CRITICAL28 Jul 2026
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open
GitHub PoC6
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.
CVE-2020-7961CRITICALunder attack28 Jul 2026
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RISK
open
GitHub PoC4
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
CVE-2026-16723CRITICAL28 Jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
bha-vin/CVE-2026-64600-Exploit
CVE-2026-64600HIGH28 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC
letsr00t/RefluxFS_CVE-2026-64600
CVE-2026-64600HIGH28 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC3
CVE-2026-53264 - Draft or Todo
CVE-2026-53264HIGH28 Jul 2026
net/sched: act_api: use RCU with deferred freeing for action lifecycle
41RISK
open
GitHub PoC11
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
CVE-2026-16232CRITICALunder attack28 Jul 2026
Authentication Bypass in the SmartConsole Login Process Using an Application Token
100RISK
open
GitHub PoC
Perl Image::WebP library. Unofficial. CVE-2026-58586
CVE-2026-58586CRITICAL28 Jul 2026
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
28RISK
open
GitHub PoC10
KSU installer for supported firmware with CVE-2026-43499
CVE-2026-43499HIGH28 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
CVE-2026-15013
CVE-2026-15013CRITICAL27 Jul 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISK
open
GitHub PoC
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-50522CRITICALunder attack27 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
CVE-2026-43499: Linux kernel futex PI use-after-free research package
CVE-2026-43499HIGH27 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC3
A POC for the recently discovered Qualys bug on COW with XFS
CVE-2026-64600HIGH27 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC10
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.
CVE-2026-54121HIGH27 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
CVE-2026-57973 is a medium-severity (CVSS 6.3) TOCTOU race condition flaw in Windows Subsystem for Linux (WSL2). It allows a local, low-privileged attacker to bypass security boundaries and perform unauthorized kernel-level tampering on the host machine without user interaction.
CVE-2026-57973MEDIUM27 Jul 2026
Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
13RISK
open
GitHub PoC35
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
CVE-2026-42533CRITICAL27 Jul 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC12
Unprivileged user to root on macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.
CVE-2026-39875HIGH27 Jul 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonom
41RISK
open
GitHub PoC1
CVE-2026-65008
CVE-2026-65008CRITICAL27 Jul 2026
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISK
open
GitHub PoC1
A poc for a vulnerability in ZTE File Manager (zte.com.cn.filer) which allows to read arbitrary files from other apps as the privileges of this file manager
CVE-2026-40000LOW27 Jul 2026
Path Traversal Vulnerability in ZTE Blade A75 5G
28RISK
open
GitHub PoC
yuimamur/CVE-2024-4367-hands-on-01
CVE-2024-4367MEDIUM27 Jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
PoC and analysis of CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware27 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Procjevt/CVE-2026-58138
CVE-2026-58138CRITICAL27 Jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
GitHub PoC
A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by comparing the vulnerable Apache HTTP Server 2.4.49 source code with the patched 2.4.51 implementation.
CVE-2021-41773HIGHunder attackransomware27 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.