Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
CVE-2026-57973 is a medium-severity (CVSS 6.3) TOCTOU race condition flaw in Windows Subsystem for Linux (WSL2). It allows a local, low-privileged attacker to bypass security boundaries and perform unauthorized kernel-level tampering on the host machine without user interaction.
CVE-2026-57973MEDIUM27 Jul 2026
Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
13RISK
open
GitHub PoC1
CVE-2026-15013
CVE-2026-15013CRITICAL27 Jul 2026
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISK
open
GitHub PoC
A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by comparing the vulnerable Apache HTTP Server 2.4.49 source code with the patched 2.4.51 implementation.
CVE-2021-41773HIGHunder attackransomware27 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
Dungsocool/CVE-2026-60137_CVE-2026-63030
CVE-2026-60137MEDIUMunder attack27 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC1
soralis0912/CVE-2026-43499-pmg110-root
CVE-2026-43499HIGH27 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC2
Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted sites — per-user email reports, core file diff against clean WordPress, PHP/JS/htaccess/image analysis, and optional AI evaluation via Claude API.
CVE-2026-63030CRITICALunder attack27 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Phucc29/CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware27 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
yuimamur/CVE-2024-4367-hands-on-01
CVE-2024-4367MEDIUM27 Jul 2026
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open
GitHub PoC
Security Advisory: Unauthenticated Memory Leak Leads To Memory Exhaustion (TinyWeb)
CVE-2026-67183HIGH26 Jul 2026
TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling
41RISK
open
GitHub PoC
Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)
CVE-2026-67185HIGH26 Jul 2026
TinyWeb 0.0.8 Path Traversal via URL Path Component
41RISK
open
GitHub PoC
Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)
CVE-2026-67184HIGH26 Jul 2026
TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
41RISK
open
GitHub PoC1
Hunt-Benito/siyuan-mcp-admin-takeover-cve-2026-66012-missing-authorization
CVE-2026-66012CRITICAL26 Jul 2026
SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP
48RISK
open
GitHub PoC6
A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability assessment, XFS reflink detection, a safe race-condition PoC, and layered mitigation using SystemTap and XFS hardening.
CVE-2026-64600HIGH26 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC
Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)
CVE-2026-66749HIGH26 Jul 2026
Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup
41RISK
open
GitHub PoC3
Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.
CVE-2026-41940CRITICALunder attackransomware26 Jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)
CVE-2026-66750MEDIUM26 Jul 2026
Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route
33RISK
open
GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
CVE-2026-66751MEDIUM26 Jul 2026
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
33RISK
open
GitHub PoC
Adding --insecure to skip ssl
CVE-2026-60137MEDIUMunder attack26 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC
Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)
CVE-2026-66752MEDIUM26 Jul 2026
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
33RISK
open
GitHub PoC23
基于内核漏洞CVE-2026-43499的本地提权适配,集成嵌入式 KernelSU.CVE-2026-43499+KernelSU越狱模式
CVE-2026-43499HIGH26 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC3
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via double-extension bypass.
CVE-2026-58480CRITICAL26 Jul 2026
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
48RISK
open
GitHub PoC
Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)
CVE-2026-67181MEDIUM26 Jul 2026
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
33RISK
open
GitHub PoC
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
CVE-2026-15981CRITICAL26 Jul 2026
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
48RISK
open
GitHub PoC
Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)
CVE-2026-66753MEDIUM26 Jul 2026
tiny-http 0.12.0 HTTP Response Splitting via Header Injection
33RISK
open
GitHub PoC
Docker-based isolated proof-of-concept lab for analysing CVE-2021-44228 (Log4Shell) for the COMP6441 Security Engineering project.
CVE-2021-44228CRITICALunder attackransomware26 Jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.
CVE-2026-54121HIGH26 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC3
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
CVE-2026-10818HIGH26 Jul 2026
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
41RISK
open
GitHub PoC4
CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (in progress)
CVE-2026-43499HIGH26 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)
CVE-2026-67182MEDIUM26 Jul 2026
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
33RISK
open
GitHub PoC1
soralis0912/CVE-2026-43499-warhol-root
CVE-2026-43499HIGH26 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.