Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,893cataloged exploits
36,846CVEs with public exploitation
24,695lab-tested
79,894 exploits
VulnCheck XDB
initial-access
CVE-2026-4480CRITICAL05 Aug 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack05 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
0xdak/CVE-2026-44024_exploit
CVE-2026-44024CRITICAL05 Aug 2026
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
48RISK
open
GitHub PoC
minwunn/wp2shell-CVE-2026-63030
CVE-2026-63030CRITICALunder attack05 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC916
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
CVE-2026-63030CRITICALunder attack05 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware05 Aug 2026
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack05 Aug 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack05 Aug 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
client-side
CVE-2024-21413CRITICALunder attack05 Aug 2026
Microsoft Outlook Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version scheme. CVE-2026-58062 / CVE-2026-8763 / CVE-2026-59650 / CVE-2026-59638
CVE-2026-58062CRITICAL05 Aug 2026
Stapled OCSP response accepted without binding to the checked certificate
48RISK
open
GitHub PoC
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything cross tenant.
CVE-2025-66390CRITICAL05 Aug 2026
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication)
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-9198CRITICALunder attack05 Aug 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-32432CRITICALunder attack05 Aug 2026
Craft CMS Allows Remote Code Execution
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-60004CRITICALunder attack05 Aug 2026
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISK
open
GitHub PoC
Detection rules and analysis for Dirty Frag (CVE-2026-43284/CVE-2026-43500) Linux kernel LPE vulnerability. Based on community research and health probe configurations.
CVE-2026-43284HIGH05 Aug 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
qflksheep/CVE-2026-67689-FineAdmin.Mvc-vulnerability
CVE-2026-67689CRITICAL05 Aug 2026
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or
48RISK
open
GitHub PoC1
CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.
CVE-2026-42533CRITICAL05 Aug 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack05 Aug 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC1
rmhowe425/PoC-CVE-2026-9198
CVE-2026-9198CRITICALunder attack05 Aug 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMunder attack05 Aug 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC13
PoCs for Wellbia XIGNCODE3 anti-cheat xhunter driver family - xhunter1.sys v2023.12.7.78 and xhunter2.sys v2026.6.1.192 (CVE-2026-15430, CVE-2026-3609).
CVE-2026-15430MEDIUM05 Aug 2026
CVE-2026-15430
33RISK
open
GitHub PoC
ICS-Park Smart Park Management System v2.0
CVE-2026-67687HIGH05 Aug 2026
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
41RISK
open
GitHub PoC
x-znn/CVE-2026-63030
CVE-2026-63030CRITICALunder attack04 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC2
CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434 | CI4 < 4.7.4
CVE-2026-63223CRITICAL04 Aug 2026
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RISK
open
GitHub PoC
0xdak/CVE-2026-52680_exploit
CVE-2026-52680CRITICAL04 Aug 2026
Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write
48RISK
open
GitHub PoC
Shams-Ul-Mehmood/CVE-2021-41773-Exploit
CVE-2021-41773HIGHunder attackransomware04 Aug 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
0xdak/CVE-2026-59243_exploit
CVE-2026-59243CRITICAL04 Aug 2026
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISK
open
GitHub PoC
Foxer131/CVE-2026-70481
CVE-2026-70481MEDIUM04 Aug 2026
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
33RISK
open
GitHub PoC1
JVBotelho/cve-2026-69243-poc-aiohttp-smuggling
CVE-2026-69243MEDIUM04 Aug 2026
AIOHTTP: HTTP request smuggling via WebSocket upgrade
33RISK
open
GitHub PoC1
pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch
CVE-2026-17566CRITICAL04 Aug 2026
pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)
48RISK
open
previouspage 34 / 2,664next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.