Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
14,946 exploits
GitHub PoC
CVE-2026-73570 PoC
CVE-2026-73570HIGHunder attack24 Aug 2026
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
91RISK
open
GitHub PoC
imbas007/RCE-CVE-2026-10520-CVE-2026-10523
CVE-2026-10520CRITICAL24 Aug 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
GitHub PoC
Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.
CVE-2019-0708CRITICALunder attackransomware24 Aug 2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC19
CVE-2026-18963
CVE-2026-18963CRITICAL24 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
h00die/POC-CVE-2026-19679
CVE-2026-19679HIGH24 Aug 2026
Improper Input Validation
41RISK
open
GitHub PoC2
CVE-2026-77806漏洞检测代码
CVE-2026-77806CRITICAL24 Aug 2026
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August
63RISK
open
GitHub PoC
Patch: SSRF leading to RCE (Microsoft Exchange Server)
CVE-2026-15502MEDIUM24 Aug 2026
AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
33RISK
open
GitHub PoC
Patch: OGNL injection (Apache Struts)
CVE-2026-10520CRITICAL24 Aug 2026
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open
GitHub PoC
Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-66906CRITICAL24 Aug 2026
Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
48RISK
open
GitHub PoC
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
CVE-2026-12087CRITICAL24 Aug 2026
Socket versions before 2.041 for Perl have an out-of-bounds heap read
48RISK
open
GitHub PoC
minh3102011/CVE-2026-18963_analyst
CVE-2026-18963CRITICAL24 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
Reproducer for CVE-2026-59230 (Apache Camel camel-mail MimeMultipart headersInline header injection) — Camel Spring Boot + Camel Quarkus
CVE-2026-59230MEDIUM24 Aug 2026
Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
33RISK
open
GitHub PoC
Patch: Command injection in GlobalProtect (Palo Alto PAN-OS)
CVE-2026-14290MEDIUM24 Aug 2026
Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute
33RISK
open
GitHub PoC
Patch: Remote code execution in SPL parsing (Splunk Enterprise)
CVE-2026-28001CRITICAL24 Aug 2026
WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability
48RISK
open
GitHub PoC
Reproducer for CVE-2026-60093 (Apache Camel camel-azure-storage-datalake downloadToFile path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-60093MEDIUM24 Aug 2026
Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
33RISK
open
GitHub PoC
Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus
CVE-2026-66907HIGH24 Aug 2026
Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
41RISK
open
GitHub PoC
Reproducer for CVE-2026-66908 (Apache Camel camel-platform-http-main JWT iss/aud not validated) — standalone camel-main
CVE-2026-66908HIGH24 Aug 2026
Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
41RISK
open
GitHub PoC
Reproducer for CVE-2026-78329 (Apache Camel camel-undertow header filter strategy not applied, websocket.* injection) — Camel Spring Boot
CVE-2026-78329CRITICAL24 Aug 2026
Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
48RISK
open
GitHub PoC2
T0w0T/POC-CVE-2026-18963
CVE-2026-18963CRITICAL24 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.
CVE-2009-065823 Aug 2026
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISK
open
GitHub PoC
chessalekin/cve-2026-9198_exploit
CVE-2026-9198CRITICALunder attack23 Aug 2026
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open
GitHub PoC4
Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2, deterministic oracle.
CVE-2026-10053HIGH23 Aug 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
41RISK
open
GitHub PoC
IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery
CVE-2026-66917HIGH23 Aug 2026
Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0
41RISK
open
GitHub PoC
Exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 — a hands-on pentesting lab writeup covering recon, exploitation, and remediation.
CVE-2011-252323 Aug 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation
CVE-2026-23744CRITICAL23 Aug 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC1
Legendile7/CVE-2026-78122-POC
CVE-2026-78122HIGH23 Aug 2026
docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
41RISK
open
GitHub PoC
h00die/POC-CVE-2026-19681
CVE-2026-19681CRITICAL23 Aug 2026
Command Injection
63RISK
open
GitHub PoC1
PoC exploit chain for CVE-2026-15718: SpiderMonkey wasm baseline compiler array.fill missing-sync -> invalid pointer -> addrOf/fakeobj -> arbitrary R/W -> RCE
CVE-2026-15718MEDIUM23 Aug 2026
Invalid pointer in the JavaScript: WebAssembly component
33RISK
open
GitHub PoC
Professional PHPMyAdmin 5.0.0 SQL Injection (CVE-2020-5504) exploitation framework with automated database enumeration, table extraction, and data dumping capabilities. Features blind injection, proxy support, JSON output, and comprehensive error handling for authorized penetration testing and security research. Author: Sudeepa Wanigarathna
CVE-2020-550423 Aug 2026
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could
35RISK
open
GitHub PoC
Password-Protected Category Bypass via JSON Format in JoomGallery
CVE-2026-66916MEDIUM23 Aug 2026
Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0
33RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.