Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android
CVE-2019-644715 Jul 2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open
GitHub PoC4
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8
CVE-2026-3891CRITICAL15 Jul 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC21
PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0
CVE-2026-3891CRITICAL15 Jul 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC3
CVE-2026-15409
CVE-2026-15409CRITICALunder attackransomware15 Jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open
GitHub PoC2
Raimu0x19/CVE-2026-13001
CVE-2026-13001CRITICAL15 Jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISK
open
GitHub PoC
WhatsWrongAndWhy/CVE-2016-8655
CVE-2016-865515 Jul 2026
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RISK
open
GitHub PoC3
A lightweight, fast tool to scan and detect the "regreSSHion" OpenSSH remote code execution vulnerability (CVE-2024-6387).
CVE-2024-6387HIGH15 Jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC2
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
CVE-2026-58138CRITICAL15 Jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open
GitHub PoC
firstlax6t/CVE-2026-36669-FengOffice
CVE-2026-36669CRITICAL15 Jul 2026
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote
48RISK
open
GitHub PoC2
CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie deserialization to write webshell via Joomla FormattedtextLogger gadget chain. Includes interactive shell, path discovery, and cleanup. For authorized security testing only.
CVE-2026-48909CRITICAL15 Jul 2026
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RISK
open
GitHub PoC
A containerized enterprise-style lab for researching and defending against CVE-2026-27483.
CVE-2026-27483HIGH15 Jul 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RISK
open
GitHub PoC10
CvE-2026-43499偏移量计算
CVE-2026-43499HIGH15 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
ctn-Qvo/CVE-2026-43499-so-build
CVE-2026-43499HIGH15 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read + delete of arbitrary documents (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46588HIGH15 Jul 2026
Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
41RISK
open
GitHub PoC
Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46585HIGH15 Jul 2026
Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
41RISK
open
GitHub PoC29
PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
CVE-2026-58635HIGH15 Jul 2026
Windows Narrator Braille Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
NeseOS-Corp/CVE-2026-50657
CVE-2026-50657MEDIUM15 Jul 2026
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
33RISK
open
GitHub PoC1
Samsung libimagecodec.quram.so OOB Write PoC
CVE-2026-21045HIGH15 Jul 2026
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
41RISK
open
GitHub PoC
Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization bypass / cross-label data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46591HIGH15 Jul 2026
Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
41RISK
open
GitHub PoC
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerability in the KVM code that has been sitting there since 2010.
CVE-2026-53359HIGH15 Jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open
GitHub PoC
My portfolio showcasing vulnerability research (CVE-2026-11989, CVE-2026-11395) and automated threat orchestration engineering (Lucius Engine, TalonVigil).
CVE-2026-11989MEDIUM15 Jul 2026
Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
33RISK
open
GitHub PoC
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection
CVE-2026-15410HIGHunder attackransomware15 Jul 2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
76RISK
open
GitHub PoC
arpit-bansal15/cve-2026-48282-pentest-lab
CVE-2026-48282CRITICAL15 Jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
75RISK
open
GitHub PoC
Panduan mitigasi Januscape (CVE-2026-53359) AlmaLinux 9.5 production-safe + scripts
CVE-2026-53359HIGH15 Jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open
GitHub PoC
exploit for CVE-2022-42889
CVE-2022-4288915 Jul 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RISK
open
GitHub PoC
The GREENDARK hospital infrastructure was configured by Dr. Gusto Rogue prior to his termination. No further details are provided.
CVE-2021-41773HIGHunder attackransomware15 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
lamaper/CVE-2026-52199
CVE-2026-52199CRITICAL15 Jul 2026
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/
48RISK
open
GitHub PoC
Kanak-CypherX/cve-2024-4577-lab
CVE-2024-4577CRITICALunder attackransomware15 Jul 2026
Argument Injection in PHP-CGI
100RISK
open
GitHub PoC
Pen Tesing Lab exploiting VSFTPD 2.3.4 backdoor via Metasploit Framework
CVE-2011-252314 Jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
This contains the Dockerfile for building and reproduing shellshock
CVE-2014-7169CRITICALunder attack14 Jul 2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.