Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
MW-HF/Drupal-CVE-2026-9082
CVE-2026-9082CRITICALunder attack11 Jul 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
1beelze/CVE-2026-14894
CVE-2026-14894CRITICAL11 Jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RISK
open
GitHub PoC2
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
CVE-2026-56291CRITICALunder attack11 Jul 2026
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
98RISK
open
GitHub PoC
An unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the database.
CVE-2026-40887CRITICAL11 Jul 2026
@vendure/core has a SQL Injection vulnerability
43RISK
open
GitHub PoC1
Dahua CVE-2026-29114
CVE-2026-29114LOW11 Jul 2026
A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that
28RISK
open
GitHub PoC
Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project demonstrates vulnerability assessment, exploitation, mitigation, and SIEM detection for Oracle WebLogic (CVE-2017-10271) and Apache Druid (CVE-2021-25646).
CVE-2017-10271HIGHunder attackransomware11 Jul 2026
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RISK
open
GitHub PoC
PoC for jenkins 2.63 CVE-2019-1003030
CVE-2019-1003030CRITICALunder attack11 Jul 2026
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RISK
open
GitHub PoC
Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel
CVE-2026-42527HIGH11 Jul 2026
Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure
41RISK
open
GitHub PoC
Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.
CVE-2012-1823CRITICALunder attack11 Jul 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHunder attack11 Jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC6
Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501
CVE-2026-43501CRITICAL11 Jul 2026
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
48RISK
open
GitHub PoC
Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS signatures.
CVE-2011-252311 Jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
WHS 4기 이희수. kr-vulhub 과제 제출물
CVE-2021-41773HIGHunder attackransomware11 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC
CVE-2026-23744CRITICAL11 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
jini135wii/CVE-2019-15107
CVE-2019-15107CRITICALunder attackransomware11 Jul 2026
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
GitHub PoC
Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8
CVE-2026-15282CRITICAL11 Jul 2026
Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
48RISK
open
GitHub PoC
Lim-ahmin/CVE-2021-43798
CVE-2021-43798HIGHunder attack11 Jul 2026
Grafana path traversal
100RISK
open
GitHub PoC
A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x
CVE-2026-38526CRITICAL11 Jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
GitHub PoC
[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)
CVE-2016-5195HIGHunder attack11 Jul 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC1
Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices. Proof-Of-Concept
CVE-2026-13768CRITICAL11 Jul 2026
Gardyn IoT Hub Use of Hard-coded Credentials
48RISK
open
GitHub PoC4
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
CVE-2026-46331HIGH11 Jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC1
Dahua CVE-2026-29116
CVE-2026-29116HIGH11 Jul 2026
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially
41RISK
open
GitHub PoC1
CVE-2026-46242
CVE-2026-46242HIGH11 Jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISK
open
GitHub PoC1
PoC untuk CVE-2026-0740: Ninja Forms File Uploads <= 3.3.26 — Unauthenticated Arbitrary File Upload yang dapat mengarah ke RCE.
CVE-2026-0740CRITICAL11 Jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC1
Dahua CVE-2026-29115
CVE-2026-29115MEDIUM11 Jul 2026
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c
33RISK
open
GitHub PoC3
This is an exploit for CVE-2026-46215 (Linux Kernel Use After Free) Adapted for Linux 7.0 !!! by Antonius (ev1lut10n / sw0rdm4n)
CVE-2026-46215HIGH11 Jul 2026
drm: Set old handle to NULL before prime swap in change_handle
41RISK
open
GitHub PoC
0x77FSec/CVE-2026-23744
CVE-2026-23744CRITICAL10 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
CVE-2026-9558CRITICAL10 Jul 2026
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi
48RISK
open
GitHub PoC
PoC for CVE-2026-56423: MISP deleteSelection broken access control (CWE-862, contributor hard-deletes other orgs' Event Reports/Sharing Groups, CVSS 8.8)
CVE-2026-56423CRITICAL10 Jul 2026
MISP Core: Broken access control allows instance-wide unauthorized deletion of event reports and sharing groups via bulk deletion endpoints
48RISK
open
GitHub PoC
CVE-2025-60787 motionEye authenticated command injection RCE PoC
CVE-2025-60787HIGH10 Jul 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.