Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
0x77FSec/CVE-2026-23744
CVE-2026-23744CRITICAL10 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
CVE-2026-51833 Advisory
CVE-2026-51833HIGH10 Jul 2026
Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can
41RISK
open
GitHub PoC
oPanel Authanticated Remote Code Execution via 'advenced/curl' Component
CVE-2026-50979HIGH10 Jul 2026
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
41RISK
open
GitHub PoC
oPanel DNS-Based Cross-Site Scripting (XSS) & Session Hijacking
CVE-2026-5098010 Jul 2026
Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote
23RISK
open
GitHub PoC
CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1
CVE-2026-54390CRITICAL10 Jul 2026
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
48RISK
open
GitHub PoC
Dr-D25/CVE-2026-49049
CVE-2026-49049HIGH10 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISK
open
GitHub PoC1
inforcqb/CVE-2026-43499-pja110
CVE-2026-43499HIGH10 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
caspy123/CVE-2026-43499
CVE-2026-43499HIGH10 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-28992 IOHIDFamily FastPathUserClient race condition PoC — security research
CVE-2026-28992MEDIUM10 Jul 2026
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7
33RISK
open
GitHub PoC
Abyssal is a high-performance Telnet vulnerability scanner for CVE-2026-24061, delivering root shells on vulnerable systems with false-positive detection.
CVE-2026-24061CRITICALunder attack10 Jul 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC1
Reproducer for CVE-2026-40858 — Apache Camel camel-infinispan remote aggregation repository unsafe deserialization (RCE)
CVE-2026-40858HIGH10 Jul 2026
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
41RISK
open
GitHub PoC
Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)
CVE-2026-40860CRITICAL10 Jul 2026
Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp
48RISK
open
GitHub PoC2
A Proof of Concept (PoC) exploit for CVE-2026-46331
CVE-2026-46331HIGH10 Jul 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC
Exploit for CVE-2022-26134
CVE-2022-26134CRITICALunder attackransomware10 Jul 2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RISK
open
GitHub PoC
Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)
CVE-2026-40859HIGH10 Jul 2026
Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled
41RISK
open
GitHub PoC
CVE-2025-60787 motionEye authenticated command injection RCE PoC
CVE-2025-60787HIGH10 Jul 2026
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
61RISK
open
GitHub PoC
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
CVE-2026-9558CRITICAL10 Jul 2026
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi
48RISK
open
GitHub PoC
Initial upload
CVE-2026-12352MEDIUM10 Jul 2026
Incorrect Authorization
33RISK
open
GitHub PoC
cazzysoci/cve-2026-48908
CVE-2026-48908CRITICAL09 Jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open
GitHub PoC
Control Web Panel (CWP) vulnerability scenario related to CVE-2026-57517
CVE-2026-57517CRITICAL09 Jul 2026
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
48RISK
open
GitHub PoC1
Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free
CVE-2026-43499HIGH09 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-50746... - Draft
CVE-2026-50746CRITICAL09 Jul 2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne
48RISK
open
GitHub PoC1
CVE-2026-50181 / GHSA-fg23-3346-88f5: Langroid path traversal advisory landing page
CVE-2026-50181HIGH09 Jul 2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
41RISK
open
GitHub PoC
Librebooking Admin RCE PoC CVE-2026-61343
CVE-2026-61343HIGH09 Jul 2026
LibreBooking path traversal
41RISK
open
GitHub PoC
johnwickakash12/CVE-2021-41773
CVE-2021-41773HIGHunder attackransomware09 Jul 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC9
tc3650/CVE-2026-43499-armv7
CVE-2026-43499HIGH09 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
Offical PoC for this cve
CVE-2026-56876HIGH09 Jul 2026
extract-zip unvalidated symlink path traversal
41RISK
open
GitHub PoC1
0x00phantom-hat/CVE-2026-12400-Exploit
CVE-2026-12400MEDIUM09 Jul 2026
FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints
33RISK
open
GitHub PoC
Reproducer for CVE-2026-40473: Apache Camel camel-mina MinaConverter.toObjectInput unsafe deserialization (RCE over TCP/UDP)
CVE-2026-40473HIGH09 Jul 2026
Apache Camel Mina: Unsafe Deserialization in MinaConverter.toObjectInput() via TCP/UDP
41RISK
open
GitHub PoC2
CVE-2026-53359漏洞补丁
CVE-2026-53359HIGH09 Jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.