Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
71,760 exploits
GitHub PoC
Langflow remote code execution exploit
CVE-2026-0770CRITICALunder attack23 May 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
98RISK
open
GitHub PoC
CVE-2026-0926 exploit. The Prodigy Commerce plugin for WordPress Local File Inclusion
CVE-2026-0926CRITICAL23 May 2026
Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]
63RISK
open
GitHub PoC
Google Dorks for detecting CMS Made Simple < 2.2.10 SQL Injection (CVE-2019-9053). Built for security auditing and patch verification.
CVE-2019-905323 May 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
logis11/CVE-2025-55423-analysis-and-reproduction
CVE-2025-55423CRITICAL22 May 2026
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr
48RISK
open
GitHub PoC
Python exploit toolkit for WordPress Crop Image RCE — CVE-2019-8942 & CVE-2019-8943
CVE-2019-894222 May 2026
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
GitHub PoC3
CVE-2026-20182 PoC - Cisco Catalyst SD-WAN Controller / Manager Authentication Bypass (CVSS 10.0)
CVE-2026-20182CRITICALunder attack22 May 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
GitHub PoC
This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by using any incorrect password in a Basic Authentication header. Attackers could abuse this flaw to create a new administrator account without prior authentication.
CVE-2026-8181CRITICAL22 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
GitHub PoC
BastianXploited/CVE-2026-8181
CVE-2026-8181CRITICAL22 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
GitHub PoC1
Detect whether a Strapi instance is vulnerable to CVE-2026-27886 (unauthenticated boolean-oracle exfiltration of administrator secrets).
CVE-2026-27886CRITICAL22 May 2026
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
48RISK
open
GitHub PoC
Pumila03/CVE-2026-6009
CVE-2026-6009HIGH22 May 2026
Jaspersoft Library Deserialisation Vulnerability
41RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-42945CRITICAL22 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
96613686/CVE-2026-45584
CVE-2026-45584HIGH22 May 2026
Microsoft Defender Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
CVE-2026-20223
CVE-2026-20223CRITICAL22 May 2026
Cisco Secure Workload Unauthorized API Access Vulnerability
48RISK
open
GitHub PoC
CVE-2026-41091 / CVE-2026-45498 Microsoft Defender vulnerability scanner
CVE-2026-41091HIGHunder attack22 May 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2024-53677CRITICAL22 May 2026
Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
70RISK
open
GitHub PoC1
PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab, empirical address discovery, OOB-verified offset sweep. Original disclosure by depthfirst.
CVE-2026-42945CRITICAL22 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC2
CVE-2026-43494
CVE-2026-43494HIGH22 May 2026
net/rds: reset op_nents when zerocopy page pin fails
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-9082CRITICALunder attack22 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
CVE-2026-42208 - LiteLLM SQL Injection vulnerability scanner for BerriAI LiteLLM proxy instances
CVE-2026-42208CRITICALunder attack22 May 2026
LiteLLM: SQL injection in Proxy API key verification
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack22 May 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack22 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-20182CRITICALunder attack22 May 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
GitHub PoC
jaf0rk/CVE-2026-5281
CVE-2026-5281HIGHunder attack22 May 2026
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RISK
open
GitHub PoC3
eprocess offset puller for relevant member offsets and function addresses for cve-2026-40369
CVE-2026-40369HIGH22 May 2026
Windows Kernel Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC2
Safely detect whether a PAN-OS target is vulnerable to CVE-2026-0265.
CVE-2026-0265HIGH22 May 2026
PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled
41RISK
open
VulnCheck XDB
denial-of-service
CVE-2026-5281HIGHunder attack22 May 2026
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
71RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2019-894222 May 2026
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL22 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
GitHub PoC
Portable Python PoC for CVE-2026-31431 (Copy Fail)
CVE-2026-31431HIGHunder attack22 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
NullByte8080/CVE-2026-36228
CVE-2026-36228HIGH22 May 2026
Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu
41RISK
open
previouspage 54 / 2,392next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.