Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC2
syxlox/CVE-2026-50369
CVE-2026-50369HIGH16 Jul 2026
Windows Remote Desktop Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
sadb98523-eng/CVE-2026-13001
CVE-2026-13001CRITICAL16 Jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISK
open
GitHub PoC
Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.
CVE-2026-15409CRITICALunder attackransomware16 Jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open
GitHub PoC
CVE-2026-43499 exploit with OnePlus Ace3 support
CVE-2026-43499HIGH16 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Sana-404/CVE-2026-8388-Mitigation-and-Detection
CVE-2026-8388MEDIUM16 Jul 2026
Incorrect boundary conditions in the JavaScript Engine: JIT component
33RISK
open
GitHub PoC
Sana-404/CVE-2026-8838-Mitigation-and-Detection
CVE-2026-8838CRITICAL16 Jul 2026
Remote Code Execution via eval() Injection in amazon-redshift-python-driver
48RISK
open
GitHub PoC52
Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.
CVE-2026-49176HIGH16 Jul 2026
Windows WalletService Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC1
CVE-2026-33017 Exploit | by infrar3d
CVE-2026-33017CRITICALunder attack16 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC6
Proof of concept for CVE-2026-54992, an MSMQ remote-read integer overflow
CVE-2026-54992HIGH16 Jul 2026
Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
41RISK
open
GitHub PoC1
ctn-Qvo/CVE-2026-43499-so-build
CVE-2026-43499HIGH15 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
Samsung libimagecodec.quram.so OOB Write PoC
CVE-2026-21045HIGH15 Jul 2026
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
41RISK
open
GitHub PoC10
CvE-2026-43499偏移量计算
CVE-2026-43499HIGH15 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization bypass / cross-label data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46591HIGH15 Jul 2026
Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
41RISK
open
GitHub PoC
Reproducer for CVE-2026-46590: Apache Camel camel-pqc key-lifecycle unsafe deserialization (FileBasedKeyLifecycleManager legacy .key migration via ObjectInputStream), incomplete remediation of CVE-2026-40048 (fixed in 4.18.3/4.21.0)
CVE-2026-46590HIGH15 Jul 2026
Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)
41RISK
open
GitHub PoC
The GREENDARK hospital infrastructure was configured by Dr. Gusto Rogue prior to his termination. No further details are provided.
CVE-2021-41773HIGHunder attackransomware15 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
WhatsWrongAndWhy/CVE-2016-8655
CVE-2016-865515 Jul 2026
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open
GitHub PoC
Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android
CVE-2019-644715 Jul 2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC
WhatsWrongAndWhy/CVE-2015-1328
CVE-2015-132815 Jul 2026
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RISK
open
GitHub PoC1
A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia
CVE-2026-43499HIGH15 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Kanak-CypherX/cve-2024-4577-lab
CVE-2024-4577CRITICALunder attackransomware15 Jul 2026
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC2
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
CVE-2026-58138CRITICAL15 Jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
GitHub PoC21
PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0
CVE-2026-3891CRITICAL15 Jul 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerability in the KVM code that has been sitting there since 2010.
CVE-2026-53359HIGH15 Jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open
GitHub PoC
seqra/cve-2026-58138
CVE-2026-58138CRITICAL15 Jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
GitHub PoC
firstlax6t/CVE-2026-36669-FengOffice
CVE-2026-36669CRITICAL15 Jul 2026
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote
48RISK
open
GitHub PoC
Panduan mitigasi Januscape (CVE-2026-53359) AlmaLinux 9.5 production-safe + scripts
CVE-2026-53359HIGH15 Jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open
GitHub PoC27
This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the websocket for file r/w and arbitrary code execution via RPC calls.
CVE-2026-15409CRITICALunder attackransomware15 Jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open
GitHub PoC
FzRsLLaSheR/CVE-2026-14960-CVE-2026-14961
CVE-2026-14960CRITICAL15 Jul 2026
CVE-2026-14960
48RISK
open
GitHub PoC
arpit-bansal15/cve-2026-48282-pentest-lab
CVE-2026-48282CRITICAL15 Jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RISK
open
GitHub PoC
CVE-2026-15409 - Dectect
CVE-2026-15409CRITICALunder attackransomware15 Jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.