Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,858cataloged exploits
36,825CVEs with public exploitation
24,695lab-tested
79,865 exploits
GitHub PoC
A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go
CVE-2025-32432CRITICALunder attack07 Aug 2026
Craft CMS Allows Remote Code Execution
100RISK
open
GitHub PoC
CVE-2026-64638
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
Shams-Ul-Mehmood/CVE-2021-3156-Project
CVE-2021-3156HIGHunder attack07 Aug 2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RISK
open
GitHub PoC53
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
CVE-2026-64638HIGH07 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
Giangdurian/CVE-2021-3129
CVE-2021-3129CRITICALunder attackransomware07 Aug 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC1
CVE-2026-44613
CVE-2026-44613MEDIUM07 Aug 2026
Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling
33RISK
open
GitHub PoC
Hunt-Benito/go-without-bounds-cve-2026-67822-stack-overflow-in-tenda-w6-s-wifissidset
CVE-2026-67822CRITICAL07 Aug 2026
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu
48RISK
open
GitHub PoC1
CVE-2026-70559
CVE-2026-70559HIGH07 Aug 2026
Dinky Unauthenticated System Configuration and Credential Disclosure via GET /api/sysConfig/getAll
41RISK
open
GitHub PoC1
Security research: Trezor Safe calldata confirmation-binding bypass vulnerability analysis. Educational proof-of-concept for hardware wallet transaction display verification.
CVE-2026-65058MEDIUM06 Aug 2026
Trezor Safe improper security check in on-device display
13RISK
open
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1
CVE-2026-66492MEDIUM06 Aug 2026
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISK
open
GitHub PoC
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
CVE-2026-49268HIGH06 Aug 2026
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
41RISK
open
GitHub PoC
tfawnies/CVE-2026-64633
CVE-2026-64633CRITICAL06 Aug 2026
A vulnerability allowing remote unauthenticated code execution on the agent host.
48RISK
open
GitHub PoC5
👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/reporting), Weaponized (reverse shell, persistence, UDF RCE, deployment, file read/write, database operations, mass scan). w/Python. 🦾 Use Ethically, Stay Legal <3
CVE-2026-58048CRITICAL06 Aug 2026
Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
48RISK
open
GitHub PoC
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)
CVE-2026-52886MEDIUM06 Aug 2026
Notepad++: session.xml backupFilePath starts_with Bypass
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-55040CRITICALunder attack06 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
CVE-2026-41293CRITICAL06 Aug 2026
Apache Tomcat: HTTP/2 request headers not validated
48RISK
open
GitHub PoC
CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.
CVE-2026-67598CRITICAL06 Aug 2026
Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php
48RISK
open
GitHub PoC
CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research
CVE-2019-697706 Aug 2026
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct
45RISK
open
GitHub PoC2
CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated, remote attackers to elevate privileges over a network.
CVE-2026-56164MEDIUMunder attack06 Aug 2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISK
open
GitHub PoC1
Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout
CVE-2026-17543HIGH06 Aug 2026
SQL injection in ext-pgsql via E'...' backslash breakout
41RISK
open
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2
CVE-2026-66491HIGH06 Aug 2026
Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3
41RISK
open
GitHub PoC58
Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)
CVE-2026-55040CRITICALunder attack06 Aug 2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
100RISK
open
GitHub PoC1
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
CVE-2026-57827CRITICAL06 Aug 2026
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
63RISK
open
GitHub PoC
Read-only N-able N-central CVE-2026-18556/CVE-2026-18577 post-exploitation IoC hunter for Windows endpoints
CVE-2026-18556HIGHunder attack06 Aug 2026
Unauthenticated administrative account takeover
83RISK
open
GitHub PoC
The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4
CVE-2026-66493MEDIUM06 Aug 2026
Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3
33RISK
open
VulnCheck XDB
initial-access
CVE-2024-2961HIGH06 Aug 2026
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4
78RISK
open
GitHub PoC
0xdak/CVE-2026-69098_exploit
CVE-2026-69098CRITICAL06 Aug 2026
kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
48RISK
open
GitHub PoC
hasan8babiker/CVE-2024-6387
CVE-2024-6387HIGH06 Aug 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC1
woshidashabi1126/CVE-2026-70553-PoC
CVE-2026-70553CRITICAL06 Aug 2026
MaxSite CMS Unauthenticated RCE via Install Endpoint
48RISK
open
GitHub PoC4
Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).
CVE-2026-18649HIGH06 Aug 2026
Gstreamer1-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
41RISK
open
previouspage 32 / 2,663next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.