Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC1
CVE-2026-41940
CVE-2026-41940CRITICALunder attackransomware24 Jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
EasyStore Joomla Pre-Auth SQL Injection via filter_sortby Direction (CVE-2026-65761, CVSS 9.3)
CVE-2026-65761CRITICAL24 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
63RISK
open
GitHub PoC4
👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit combo/unsigned/xsw/nameid/all, --shodan integration, --tor support, mass scanning, JSON/CSV/JSONL output, cookie validation. 🛡️ CVSS 9.9 Critical - Use Ethically, Stay Legal. 🔒
CVE-2026-60206CRITICAL24 Jul 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RISK
open
GitHub PoC
Giangdurian/CVE-2026-63030-CVE-2026-60137
CVE-2026-63030CRITICALunder attack24 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
ange-primiterra/CVE-2026-47761
CVE-2026-47761HIGH24 Jul 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
41RISK
open
GitHub PoC
Security Advisory: Out-of-Bounds Read in facil.io MIME Parser leads to Server crash
CVE-2026-66729HIGH24 Jul 2026
facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser
41RISK
open
GitHub PoC1
CVE-2021-44228 Log4Shell - Apache Log4j2 JNDI Injection RCE
CVE-2021-44228CRITICALunder attackransomware24 Jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC
is an advanced security research framework designed to model, analyze, and demonstrate Local Privilege Escalation (LPE) mechanics associated with kernel-level race conditions and filesystem structure vulnerabilities (CVE-2026-64600 / RefluXFS)
CVE-2026-64600HIGH24 Jul 2026
xfs: resample the data fork mapping after cycling ILOCK
41RISK
open
GitHub PoC1
React2Shell is a proof-of-concept exploit for CVE-2025-55182 affecting vulnerable React Server Components (RSC) implementations in Next.js
CVE-2025-55182CRITICALunder attackransomware24 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
最原始的
CVE-2026-43499HIGH24 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via UC_KEY encryption oracle token reuse. CVSS 9.1. Full-featured tool with version detection, multi-payload attacks, interactive shell, and automated exploitation. Authorized testing only.
CVE-2026-49952CRITICAL24 Jul 2026
Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
63RISK
open
GitHub PoC
kxom9ks/CVE-2024-27198-TeamCity
CVE-2024-27198CRITICALunder attackransomware24 Jul 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC
kxom9ks/CVE-2024-27198
CVE-2024-27198CRITICALunder attackransomware24 Jul 2026
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open
GitHub PoC
Reproduction of cve-2024-23897-jenkins_lfi_reproduction
CVE-2024-23897CRITICALunder attackransomware24 Jul 2026
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open
GitHub PoC1
PoC for CVE-2026-65650 - Elgg avatar upload DoS
CVE-2026-65650MEDIUM24 Jul 2026
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
33RISK
open
GitHub PoC
risorse di ricerca per cve-2026-7228
CVE-2026-7228MEDIUM24 Jul 2026
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RISK
open
GitHub PoC
Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass
CVE-2026-9198CRITICALunder attack24 Jul 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC33
cve cve-2026-60206 weblogic saml exploit poc vulnerability oracle scanner security
CVE-2026-60206CRITICAL24 Jul 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
48RISK
open
GitHub PoC
Security Advisory: Negative Chunk-Size Parsing Causes Memory Corruption in facil.io
CVE-2026-66731HIGH24 Jul 2026
facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
41RISK
open
GitHub PoC
Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field
CVE-2026-66748HIGH24 Jul 2026
Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field
41RISK
open
GitHub PoC
manfredgabriel/cve-2021-43798-lab
CVE-2021-43798HIGHunder attack24 Jul 2026
Grafana path traversal
100RISK
open
GitHub PoC
blue-chocolates/CVE-2016-10033
CVE-2016-10033CRITICALunder attack24 Jul 2026
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISK
open
GitHub PoC
Reproduction of cve-2024-3400-panos_rce_reproduction
CVE-2024-3400CRITICALunder attackransomware24 Jul 2026
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RISK
open
GitHub PoC
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
CVE-2015-132824 Jul 2026
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC
Reproduction of cve-2025-0282-ivanti_rce_reproduction
CVE-2025-0282CRITICALunder attackransomware24 Jul 2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RISK
open
GitHub PoC
sbimoxa/cve-2021-43798-lab
CVE-2021-43798HIGHunder attack24 Jul 2026
Grafana path traversal
100RISK
open
GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
CVE-2025-5777CRITICALunder attackransomware23 Jul 2026
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open
GitHub PoC
finding by nvth
CVE-2026-59880HIGH23 Jul 2026
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RISK
open
GitHub PoC
CVE Reproduction: cve-2026-0770-langflow_rce_reproduction
CVE-2026-0770CRITICALunder attack23 Jul 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Dynamo2k1/CVE-2026-33017
CVE-2026-33017CRITICALunder attack23 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.