Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,475Referência 23,360GitHub PoC 15,228VulnCheck XDB 8,946Nuclei 4,390Metasploit 3,501✓ verified onlyrecentpopularrisk
79,900 exploits
GitHub PoC★ 325
Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284
In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the
41RISK
open ↗GitHub PoC
CVE Reproduction: cve-2025-5777-citrixbleed2_reproduction
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open ↗GitHub PoC
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open ↗GitHub PoC★ 5
soralis0912/CVE-2026-43499-aristotle-apk
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 1
0xdak/CVE-2026-56121_exploit
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISK
open ↗GitHub PoC
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
21RISK
open ↗GitHub PoC
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling
48RISK
open ↗GitHub PoC★ 28
YellowKey free tool for the CVE-2026-45585 BitLocker bypass vulnerability on Windows 10/11. Covered on Tom's Hardware: extract recovery keys, apply remediation, test bypass mitigation and manage BitLocker encryption state. Download YellowKey
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open ↗VulnCheck XDB
local
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RISK
open ↗VulnCheck XDB
initial-access
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
Netlogon Elevation of Privilege Vulnerability
100RISK
open ↗GitHub PoC★ 12
DavidCarliez/CVE-2026-66804-CrossDevice-LPE
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 1
CVE-2021-41773 Apache
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗GitHub PoC
0xdak/CVE-2026-63766_exploit
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
48RISK
open ↗GitHub PoC★ 1
Metabase CVE-2026-59827 Vulnerability Scanner
Metabase: Unsafe Deserialization of H2 Query Results
48RISK
open ↗VulnCheck XDB
initial-access
PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
100RISK
open ↗GitHub PoC
finding by nvth
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
21RISK
open ↗VulnCheck XDB
info-leak
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
100RISK
open ↗VulnCheck XDB
initial-access
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
initial-access
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open ↗GitHub PoC★ 4
soralis0912/CVE-2026-43499-aristotle
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open ↗GitHub PoC★ 1
CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion
Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint
41RISK
open ↗GitHub PoC
Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)
ML-KEM ARM64 NEON ciphertext comparison only compares half of the input
33RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.