Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)
CVE-2026-67181MEDIUM26 Jul 2026
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
33RISK
open
GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)
CVE-2026-66750MEDIUM26 Jul 2026
Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route
33RISK
open
GitHub PoC
Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)
CVE-2026-66751MEDIUM26 Jul 2026
Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room
33RISK
open
GitHub PoC
Security Advisory for CVE-2026-51565
CVE-2026-51565MEDIUM25 Jul 2026
Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attacker
33RISK
open
GitHub PoC
Security Advisory for CVE-2026-51564
CVE-2026-51564MEDIUM25 Jul 2026
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external
33RISK
open
GitHub PoC40
CVE-2026-50522 PoC
CVE-2026-50522CRITICALunder attack25 Jul 2026
Microsoft SharePoint Remote Code Execution Vulnerability
100RISK
open
GitHub PoC2
CVE-2026-54121
CVE-2026-54121HIGH25 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
CVE-2026-54121 - Draft
CVE-2026-54121HIGH25 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor report. Fixed in 1.0.0.9.74.
CVE-2026-12960MEDIUM25 Jul 2026
An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o
33RISK
open
GitHub PoC
Auth Bypass in inetutils-telnetd
CVE-2026-24061CRITICALunder attack25 Jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC2
Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.
CVE-2026-48908CRITICAL25 Jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open
GitHub PoC1
CypherHippie/CVE-2026-66804
CVE-2026-66804HIGH25 Jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC3
Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.
CVE-2026-63030CRITICALunder attack25 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC1
CVE-2026-16723
CVE-2026-16723CRITICAL25 Jul 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.
CVE-2026-60206CRITICAL25 Jul 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RISK
open
GitHub PoC17
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.
CVE-2026-43499HIGH25 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC5
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)
CVE-2026-43499HIGH25 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Manage BitLocker encrypted drives on Windows. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
CVE-2026-45585MEDIUM25 Jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
GitHub PoC
Manage BitLocker encrypted drives on Windows 10 and 11. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.
CVE-2026-45585MEDIUM25 Jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
GitHub PoC2
7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap
CVE-2026-14266HIGH25 Jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
CVE-2026-61946: Unauthenticated IDOR in Easy Appointments <= 3.12.27
CVE-2026-61946MEDIUM25 Jul 2026
WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability
33RISK
open
GitHub PoC
CVE-2026-54900, CVE-2026-54902 - Draft
CVE-2026-54900MEDIUM25 Jul 2026
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
33RISK
open
GitHub PoC1
PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)
CVE-2026-65694HIGH25 Jul 2026
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
56RISK
open
GitHub PoC27
👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒
CVE-2026-54121HIGH25 Jul 2026
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
sbimoxa/cve-2021-43798-lab
CVE-2021-43798HIGHunder attack24 Jul 2026
Grafana path traversal
100RISK
open
GitHub PoC4
👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit combo/unsigned/xsw/nameid/all, --shodan integration, --tor support, mass scanning, JSON/CSV/JSONL output, cookie validation. 🛡️ CVSS 9.9 Critical - Use Ethically, Stay Legal. 🔒
CVE-2026-60206CRITICAL24 Jul 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RISK
open
GitHub PoC
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
CVE-2015-132824 Jul 2026
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC1
CVE-2026-41940
CVE-2026-41940CRITICALunder attackransomware24 Jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
manfredgabriel/cve-2021-43798-lab
CVE-2021-43798HIGHunder attack24 Jul 2026
Grafana path traversal
100RISK
open
GitHub PoC
Lite-os15/Lab-001-Gitea-CVE-2026-20896-
CVE-2026-20896CRITICAL24 Jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.