Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,264GitHub PoC 15,172VulnCheck XDB 8,920Nuclei 4,373Metasploit 3,493✓ verified onlyrecentpopularrisk
79,526 exploits
VulnCheck XDB
initial-access
Langflow code Code Injection Remote Code Execution Vulnerability
48RISK
open ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗GitHub PoC
CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open ↗Exploit-DB
Payload CMS 3.72.0 - Blind SQL Injection
Payload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
48RISK
open ↗GitHub PoC★ 1
Ghxstsec/CVE-2026-39987
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
100RISK
open ↗Exploit-DB
EasyAppointments 1.5.1 - Blind SQL Injection
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp
48RISK
open ↗GitHub PoC★ 2
Keycloak reset-credentials flow bypass
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗Exploit-DB
miniOrange 5.4.3 - Unauthenticated Auth Bypass
SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion
48RISK
open ↗GitHub PoC
pervinzahidli/CVE-2026-75855
ArcadeDB before 26.8.1 Path Traversal via create/drop database
41RISK
open ↗GitHub PoC★ 10
CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open ↗GitHub PoC
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open ↗GitHub PoC★ 1
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow
48RISK
open ↗GitHub PoC
CVE-2026-82329 - Draft or TODO
Potential authentication bypass leading to administrative access in Artifactory
93RISK
open ↗GitHub PoC★ 1
Poc of CVE-2026-13753
Certain HP DeskJet All in One – Potential Information Disclosure
41RISK
open ↗GitHub PoC
CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open ↗GitHub PoC
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
41RISK
open ↗Exploit-DB
Grav CMS 2.0.7 - RCE
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
48RISK
open ↗Exploit-DB
Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200
38RISK
open ↗GitHub PoC
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
48RISK
open ↗VulnCheck XDB
initial-access
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
100RISK
open ↗VulnCheck XDB
initial-access
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗Exploit-DB
Langflow 1.8.4 - Path Traversal to Remote Code Execution
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RISK
open ↗GitHub PoC
Reflected XSS via search GET Parameter in Phoca Download
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
33RISK
open ↗GitHub PoC★ 1
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗VulnCheck XDB
initial-access
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open ↗GitHub PoC
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
48RISK
open ↗GitHub PoC
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISK
open ↗GitHub PoC★ 2
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
41RISK
open ↗GitHub PoC
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
85RISK
open ↗GitHub PoC
joaovicdev/EXPLOIT-CVE-2026-56121
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.