Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC2
Pre-auth arbitrary file upload RCE exploit for iCagenda Joomla extension < 4.0.8 (CVSS 10.0)
CVE-2026-48939CRITICALunder attack05 Jul 2026
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
98RISK
open
GitHub PoC2
Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated Stored Cross-Site Scripting Proof of Concept
CVE-2026-10104MEDIUM05 Jul 2026
Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter
33RISK
open
GitHub PoC6
Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")
CVE-2026-20896CRITICAL05 Jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
GitHub PoC
 CVE-2026-49049 - Unauthenticated File Deletion, Arbitrary Write & XSS Injection for Helix3 Joomla Extension
CVE-2026-49049HIGH05 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISK
open
GitHub PoC6
Epson Printer RAW Protocol Exploit Framework
CVE-2026-39047HIGH05 Jul 2026
Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Prin
21RISK
open
GitHub PoC
Eliot-code/CVE-2026-22874-PoC
CVE-2026-22874CRITICAL05 Jul 2026
Gitea webhook and migration allow-list filtering permits SSRF
48RISK
open
GitHub PoC
bayu06802/CVE-2026-48908
CVE-2026-48908CRITICAL05 Jul 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open
GitHub PoC
This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an internal CGI endpoint vulnerable to Shellshock (CVE-2014-6271). Remote command execution was confirmed using an out-of-band (OAST) DNS callback, showcasing the complete attack chain, technical analysis.
CVE-2014-6271CRITICALunder attack05 Jul 2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC
Proof of Concept (PoC) for CVE-2026-49975 – HTTP/2 server memory exhaustion attack leveraging HPACK amplification and connection retention (HTTP/2 Slowloris).
CVE-2026-49975HIGH05 Jul 2026
Apache HTTP Server: mod_http2 denial of service
53RISK
open
GitHub PoC4
Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)
CVE-2026-8713CRITICAL05 Jul 2026
Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
63RISK
open
GitHub PoC
MESLIMOHAMEDM22005188/path-traversal-CVE-2026-14628
CVE-2026-14628MEDIUM05 Jul 2026
NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal
33RISK
open
GitHub PoC1
CVE-2026-34038: Authenticated Remote Command Injection in Coolify
CVE-2026-34038CRITICAL04 Jul 2026
Coolify authenticated remote command injection leading to RCE and secret exfiltration
48RISK
open
GitHub PoC1
caterscam/CVE-2026-5524-PoC
CVE-2026-5524CRITICAL04 Jul 2026
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
48RISK
open
GitHub PoC4
Read-only vulnerability scanner for CVE-2026-49049 — Helix3 Joomla plugin unauthenticated AJAX handler
CVE-2026-49049HIGH04 Jul 2026
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
56RISK
open
GitHub PoC5
Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings + Crowdfense comparison
CVE-2026-34197HIGHunder attack04 Jul 2026
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
100RISK
open
GitHub PoC
Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.
CVE-2026-23869HIGH04 Jul 2026
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-
41RISK
open
GitHub PoC2
PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover
CVE-2026-54415HIGH04 Jul 2026
Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
41RISK
open
GitHub PoC1
💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell
CVE-2026-57517CRITICAL04 Jul 2026
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
48RISK
open
GitHub PoC2
CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.
CVE-2026-22874CRITICAL04 Jul 2026
Gitea webhook and migration allow-list filtering permits SSRF
48RISK
open
GitHub PoC
Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)
CVE-2026-23744CRITICAL04 Jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
CVE-2026-42533CRITICAL04 Jul 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC19
CVE-2026-46242
CVE-2026-46242HIGH04 Jul 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISK
open
GitHub PoC
PoC of Langflow CVE-2026-33017
CVE-2026-33017CRITICALunder attack04 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
Unauthenticated RCE in Langflow <1.9.0 (CVE-2026-33017) Exploit
CVE-2026-33017CRITICALunder attack04 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
CVE-2026-59243 — Apache Airflow FAB Auth Manager JWT signature bypass (embargoed until Apache advisory)
CVE-2026-59243CRITICAL04 Jul 2026
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISK
open
GitHub PoC
Casdoor version 2.362.0
CVE-2026-9090CRITICAL04 Jul 2026
CVE-2026-9090
48RISK
open
GitHub PoC30
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).
CVE-2026-42533CRITICAL04 Jul 2026
NGINX Map directive and Regex matching vulnerability
48RISK
open
GitHub PoC4
PoC for CVE-2026-53360: guest-triggered heap out-of-bounds read/write in KVM SEV-SNP Page State Change (PSC) handling.
CVE-2026-53360HIGH04 Jul 2026
KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use
41RISK
open
GitHub PoC3
CVE-2026-54998 RCE Exploit
CVE-2026-54998HIGH04 Jul 2026
Microsoft Exchange Online Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC3
📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE
CVE-2026-56290CRITICAL04 Jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.