Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,360GitHub PoC 15,228VulnCheck XDB 8,946Nuclei 4,390Metasploit 3,501✓ verified onlyrecentpopularrisk
79,900 exploits
GitHub PoC★ 1
Wolf CMS <= 0.8.3.1 - RCE via Arbitrary File Write
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
41RISK
open ↗VulnCheck XDB
initial-access
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗VulnCheck XDB
denial-of-service
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RISK
open ↗GitHub PoC★ 1
PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)
Single Sign On For TNG <= 2.0.0 - Unauthenticated Privilege Escalation via Unverified Password Change
48RISK
open ↗VulnCheck XDB
info-leak
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open ↗GitHub PoC
Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection engineering, threat hunting, incident response, and Kubernetes security implications.
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open ↗GitHub PoC★ 1
Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗GitHub PoC
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
28RISK
open ↗GitHub PoC
Authenticated Blind OS Command Injection in ClearOS
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
41RISK
open ↗GitHub PoC★ 2
mahfuzreham/OVSwrap-CVE-2026-64531-Mitigation-Tool
net: openvswitch: reject oversized nested action attrs
41RISK
open ↗GitHub PoC
Unauthenticated RCE in DBGate <= 7.1.8
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
63RISK
open ↗GitHub PoC★ 3
LuZe0y/pd2425-cve-2026-43499-config
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 10
GhostLock (CVE-2026-43499) kernel exploit for Poco M6 Pro (emerald) with locked bootloader
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 1
CVE-2026-54121(CertiGhost) without MachineAccountQuota POC
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 1
This is N-day patch we releasing by testing our model capabilities
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open ↗GitHub PoC★ 4
GhostLock (CVE-2026-43499) exploit for POCO F3 GT (aresin) — MediaTek Dimensity 1200, Linux 4.14.186 ARM64 kernel privilege escalation via futex PI chain manipulation
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗VulnCheck XDB
initial-access
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
85RISK
open ↗VulnCheck XDB
initial-access
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open ↗GitHub PoC★ 4
A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. The CA can be coerced into authenticating back to attacker-controlled infrastructure and then issuing a certificate that impersonates a Domain Controller.
Active Directory Certificate Services Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open ↗GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RISK
open ↗GitHub PoC
This is the compiled version. This is not my program though. This is only for directly downloading the compiled version in labs where there is no gcc
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open ↗GitHub PoC
Exploit for CVE-2020-3952 in vCenter 6.7
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RISK
open ↗GitHub PoC★ 3
CVE-2026-66066 + File Read, RCE, Scanner, Lab
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
68RISK
open ↗GitHub PoC★ 1
Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
33RISK
open ↗VulnCheck XDB
info-leak
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
100RISK
open ↗GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open ↗GitHub PoC
CVE-2026-8337 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS that affects the Survey feature. Unlike CVE-2026-8347 (which involved Express associations), this vulnerability allows an unauthenticated attacker to participate in a restricted/private survey under specific site configurations.
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
33RISK
open ↗GitHub PoC
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open ↗VulnCheck XDB
initial-access
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.