Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
14,995 exploits
GitHub PoC
patched ffmpeg-tools for jellyfin to patch CVE-2026-8461 aka PixelSmash
CVE-2026-8461HIGH27 Jun 2026
Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder
41RISK
open
GitHub PoC
CVE-2026-46331 - Draft
CVE-2026-46331HIGH27 Jun 2026
net/sched: fix pedit partial COW leading to page cache corruption
41RISK
open
GitHub PoC59
cve-2026-48907 scanner
CVE-2026-48907CRITICALunder attack27 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC1
WP Full Stripe Free <= 8.4.3 - Missing Authorization
CVE-2026-12432MEDIUM27 Jun 2026
Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
33RISK
open
GitHub PoC8
OpenSTAManager-RCE-Exploit-CVE-2026-38751
CVE-2026-38751HIGH27 Jun 2026
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
41RISK
open
GitHub PoC
CVE-2026-48907 is a CVSS 10.0 pre-auth RCE in Joomla Content Editor affecting all versions ≤ 2.9.99.4. The Grayxploit team breaks down the 3-weakness chain — missing auth, no extension validation, and an unsafe upload flag — that lets attackers pop a shell in 3 HTTP requests.
CVE-2026-48907CRITICALunder attack27 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
Hunt-Benito/traefik-stripprefix-auth-bypass-cve-2026-48020-path-normalization
CVE-2026-48020HIGH27 Jun 2026
Traefik StripPrefix Route-Level Auth Bypass via Path Normalization
41RISK
open
GitHub PoC
PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.
CVE-2026-5366CRITICAL27 Jun 2026
Git Argument Injection in prefecthq/prefect
48RISK
open
GitHub PoC
Defensive analysis and non-weaponized validation of CVE-2016-5195 (Dirty COW), including root-cause research, patch analysis, and reproducible evidence.
CVE-2016-5195HIGHunder attack27 Jun 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC148
CVE-2026-43499 PoC
CVE-2026-43499HIGH27 Jun 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
kyukazamiqq/CVE-2026-24061
CVE-2026-24061CRITICALunder attack27 Jun 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC2
Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation harness. Detection and prevention only — no exploit code. TLP:CLEAR.
CVE-2026-43503HIGH27 Jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISK
open
GitHub PoC3
CVE-2026-0073-Android-ADBD-bypass-POC汉化版
CVE-2026-0073HIGH27 Jun 2026
In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err
41RISK
open
GitHub PoC
SugiB3o/CVE-2026-31431
CVE-2026-31431HIGHunder attack27 Jun 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC4
SQL Injection at Cacti
CVE-2026-40083HIGH27 Jun 2026
Cacti: SQL Injection in managers.php
41RISK
open
GitHub PoC
Cacti <= 1.2.30
CVE-2026-39938CRITICAL26 Jun 2026
Cacti: Unauthenticated RCE on Graph Image
48RISK
open
GitHub PoC
A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace.
CVE-2026-34213MEDIUM26 Jun 2026
Docmost has cross-page attachment overwrite via flawed attachmentId overwrite validation
33RISK
open
GitHub PoC
Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor in the Docmost origin.
CVE-2026-34212MEDIUM26 Jun 2026
Docmost page content has stored XSS via unsanitized attachment URLs
33RISK
open
GitHub PoC1
CVE-2026-8932
CVE-2026-8932HIGH26 Jun 2026
incomplete mTLS config matching in conn reuse
41RISK
open
GitHub PoC11
CVE-2026-26980 - Ghost CMS Content API SQL Injection
CVE-2026-26980CRITICAL26 Jun 2026
Ghost has a SQL Injection in its Content API
85RISK
open
GitHub PoC
A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public share viewers could still leak through public share search results.
CVE-2026-33146MEDIUM26 Jun 2026
Docmost's Public Share Search Exposes Metadata of Restricted Children
33RISK
open
GitHub PoC1
Ghost CMS Content API Blind SQL Injection
CVE-2026-26980CRITICAL26 Jun 2026
Ghost has a SQL Injection in its Content API
85RISK
open
GitHub PoC1
CVE-2026-24207 — NVIDIA Triton SageMaker auth bypass to unauth RCE. Detection script, bypass demo, RCE-chain PoC, and IDS rules.
CVE-2026-24207CRITICAL26 Jun 2026
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes
63RISK
open
GitHub PoC4
aexdyhaxor/CVE-2026-43503-DirtyClone
CVE-2026-43503HIGH26 Jun 2026
net: skbuff: propagate shared-frag marker through frag-transfer helpers
41RISK
open
GitHub PoC
12hrformat/CVE-2026-35273-POC
CVE-2026-35273CRITICALunder attackransomware26 Jun 2026
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana
100RISK
open
GitHub PoC
Flowiseai Flowise Auth Bypass Vulnerability Proof of Concept
CVE-2025-58434CRITICAL26 Jun 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISK
open
GitHub PoC3
CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research
CVE-2026-20251HIGH26 Jun 2026
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
53RISK
open
GitHub PoC
scanner for CVE-2020-0796
CVE-2020-0796CRITICALunder attackransomware26 Jun 2026
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RISK
open
GitHub PoC
Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration, and credential cracking prep.
CVE-2007-244726 Jun 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
CVE-2026-12415-or-CVE-2026-12416.py
CVE-2026-12415CRITICAL26 Jun 2026
Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.