Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC
CVE-2026-59243 — Apache Airflow FAB Auth Manager JWT signature bypass (embargoed until Apache advisory)
CVE-2026-59243CRITICAL04 Jul 2026
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
48RISK
open
GitHub PoC2
PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover
CVE-2026-54415HIGH04 Jul 2026
Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover
41RISK
open
GitHub PoC
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore.
CVE-2026-53753CRITICAL03 Jul 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RISK
open
GitHub PoC
Pardus Software Local Privilege Escalation PoC - affected from <= 1.0.4
CVE-2026-14459HIGH03 Jul 2026
Argument Injection in TUBITAK BILGEM's pardus-software
41RISK
open
GitHub PoC4
# CVE-2026-28995 Proof of Concept for CVE-2026-28995 — Path Traversal vulnerability in App Intents on iOS 26.4.2 and below.
CVE-2026-28995HIGH03 Jul 2026
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 an
41RISK
open
GitHub PoC1
1beelze/CVE-2026-11387
CVE-2026-11387CRITICAL03 Jul 2026
SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
63RISK
open
GitHub PoC5
☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE
CVE-2026-44825HIGH03 Jul 2026
Apache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure users
56RISK
open
GitHub PoC1
CVE-2026-49468 — LiteLLM (<1.84.0) unauthenticated auth bypass via Host-header route confusion. PoC + docker lab.
CVE-2026-49468CRITICAL03 Jul 2026
LiteLLM: Authentication Bypass via Host Header Injection
48RISK
open
GitHub PoC
Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0
CVE-2026-36851HIGH03 Jul 2026
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
41RISK
open
GitHub PoC
Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape
CVE-2026-53362HIGHunder attack03 Jul 2026
ipv6: account for fraggap on the paged allocation path
71RISK
open
GitHub PoC1
CVE-2026-8451
CVE-2026-8451HIGH03 Jul 2026
Insufficient input validation leading to memory overread
46RISK
open
GitHub PoC
CVE-2017-12615 - Apache Tomcat Remote Code Execution (RCE)
CVE-2017-12615HIGHunder attackransomware03 Jul 2026
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RISK
open
GitHub PoC2
Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter
CVE-2026-56290CRITICAL03 Jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISK
open
GitHub PoC
kn9annihilator/CVE-2011-2523-vsFTPd-2.3.4-Writeup
CVE-2011-252303 Jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open
GitHub PoC
This repository contains a proof-of-concept (PoC) exploit for CVE-2026-38751, affecting OpenSTAManager ≤ 2.10. The vulnerability allows an authenticated attacker to upload a malicious module via the module update functionality, leading to arbitrary file upload and remote code execution (RCE).
CVE-2026-38751HIGH02 Jul 2026
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
41RISK
open
GitHub PoC
Crawl4AI <= 0.8.6 pre-auth RCE via AST sandbox escape (gi_frame.f_back.f_builtins chain) — CVSS 10.0
CVE-2026-53753CRITICAL02 Jul 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RISK
open
GitHub PoC2
Python POC, Exploit for CVE-2026-33017
CVE-2026-33017CRITICALunder attack02 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
CVE-2026-55726: Publicly Listable Azure Blob Storage Container (device logs) - Gardyn (ICSA-26-183-03)
CVE-2026-55726MEDIUM02 Jul 2026
Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere
33RISK
open
GitHub PoC7
SimpleHelp OIDC Authentication Bypass PoC
CVE-2026-48558CRITICAL02 Jul 2026
SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
53RISK
open
GitHub PoC
Proof-of-concept exploit and lab environment for CVE-2026-25194
CVE-2026-25194LOW02 Jul 2026
Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adve
28RISK
open
GitHub PoC
Gogs has Path Traversal in organization name that results in RCE through Git hooks
CVE-2026-52813CRITICAL02 Jul 2026
Gogs: Path Traversal in organization name results in RCE through Git hooks
48RISK
open
GitHub PoC
CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)
CVE-2026-13768CRITICAL02 Jul 2026
Gardyn IoT Hub Use of Hard-coded Credentials
48RISK
open
GitHub PoC2
dinosn/CVE-2026-25243-debugfree
CVE-2026-25243HIGH02 Jul 2026
redis-server RESTORE invalid memory access may allow remote code execution
41RISK
open
GitHub PoC
CVE-2026-54477: Admin Panel Missing Security Headers (clickjacking/XSS) - Gardyn (ICSA-26-183-03)
CVE-2026-54477MEDIUM02 Jul 2026
Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
33RISK
open
GitHub PoC
BastianXploited/CVE-2026-0740-mass
CVE-2026-0740CRITICAL02 Jul 2026
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open
GitHub PoC
DESIGN AND IMPLEMENTATION OF A VULNERABILITY SCANNER FOR CVE-2026-45498 IN MICROSOFT DEFENDER
CVE-2026-45498MEDIUMunder attack02 Jul 2026
Microsoft Defender Denial of Service Vulnerability
55RISK
open
GitHub PoC1
kaleth4/CVE-2026-20896
CVE-2026-20896CRITICAL02 Jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
GitHub PoC
Gorse < 0.5.10 contains an authentication bypass caused by empty admin_api_key in /api/dump and /api/restore endpoints, letting unauthenticated remote attackers access and modify protected data, exploit requires default empty admin_api_key configuration.
CVE-2026-56782CRITICAL02 Jul 2026
Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints
63RISK
open
GitHub PoC
Hunt-Benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection
CVE-2026-58116CRITICAL02 Jul 2026
LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
48RISK
open
GitHub PoC
kaleth4/CVE-2026-55200
CVE-2026-55200CRITICAL02 Jul 2026
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.