Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,360GitHub PoC 15,228VulnCheck XDB 8,946Nuclei 4,390Metasploit 3,501✓ verified onlyrecentpopularrisk
79,900 exploits
GitHub PoC
fastjson vulnerability scanner - detect fastjson in JARs and Spring Boot fat-JARs, check exposure to CVE-2026-16723, and verify whether you already run the official patch 1.2.84. Zero-dependency offline CLI. fastjson 漏洞检测与排查工具:一条命令扫描依赖,支持 fat-JAR 与 shaded 依赖,并判定是否已升到官方补丁版本 1.2.84。
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open ↗GitHub PoC
This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Privilege Escalation via JSON Parsing Bypass | 🔴 Critical | | **CVE-2017-12636** | Remote Code Execution via Query Server | 🔴 Critical |
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RISK
open ↗GitHub PoC
SQL injection in PyAthena via DefaultParameterFormatter (CVE-2026-65321)
PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS
48RISK
open ↗VulnCheck XDB
local
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects
71RISK
open ↗VulnCheck XDB
local
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
68RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-9997-VPN-Split-Tunneling-Bypass-via-DHCP-Option-Injection
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende
41RISK
open ↗VulnCheck XDB
info-leak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open ↗VulnCheck XDB
info-leak
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RISK
open ↗VulnCheck XDB
initial-access
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open ↗GitHub PoC★ 2
CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗VulnCheck XDB
info-leak
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open ↗VulnCheck XDB
initial-access
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗GitHub PoC★ 1
Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector
Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State
41RISK
open ↗GitHub PoC★ 3
CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload bypass using image magic bytes. Fixed in v4.7.4.
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
48RISK
open ↗GitHub PoC
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker lab.
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
48RISK
open ↗GitHub PoC
0xdak/CVE-2026-69083_exploit
SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent
48RISK
open ↗GitHub PoC
DharmarajPS/pdfjs-cve-2024-4367-poc
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js c
55RISK
open ↗GitHub PoC
Code injection (RCE) in datamodel-code-generator via unvalidated customBasePath (CVE-2026-63720)
datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
41RISK
open ↗GitHub PoC
Procjevt/CVE-2026-63030
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC
sam00/POC-CVE-2026-54121-Certighost
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-8888-Printer-Firmware-Unsigned-Update-via-HTTP
CVE-2026-8888
41RISK
open ↗GitHub PoC★ 1
CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11103-GraphQL-Batching-Alias-Rate-Limit-Bypass
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to
41RISK
open ↗GitHub PoC
Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path combined with mass-assignment in PUT /api/v1/document-store/store/:id. Allows full compromise via /root/.flowise/encryption.key read. Distinct from CVE-2025-71338 (fixed in 2.2.4).
Flowise - Arbitrary File Write to Remote Code Execution via document-store API
48RISK
open ↗GitHub PoC★ 17
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
100RISK
open ↗GitHub PoC
wpsqli full SQLi extractor + dumper for CVE-2026-60137
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open ↗GitHub PoC
George0Papasotiriou/CVE-2026-11105-Stack-Buffer-Overflow-in-Custom-Base64-Decoder
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.