Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,900cataloged exploits
36,847CVEs with public exploitation
24,695lab-tested
79,900 exploits
GitHub PoC313
A cPanel and WHM authentication bypassing tool
CVE-2026-41940CRITICALunder attackransomware20 Jul 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
GitHub PoC
PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header filter and overrides the producer's configured topic, injecting an attacker-forged record onto a privileged Kafka topic (cross-topic injection). Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49098MEDIUM20 Jul 2026
Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic
33RISK
open
GitHub PoC
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030CRITICALunder attack20 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC1
PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange headers, hijacking the tool route's exec: sink for RCE. Fixed in 4.14.8/4.18.3/4.21.0.
CVE-2026-49042HIGH20 Jul 2026
Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters
41RISK
open
VulnCheck XDB
info-leak
CVE-2026-60137MEDIUMunder attack20 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack20 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-63030CRITICALunder attack20 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
CVE-2026-43499-cloudflare-gate签名授权计算
CVE-2026-43499HIGH19 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC17
Yellowkey bitlocker CVE-2026-45585 provides an open-source utility manager to extract, backup, and organize BitLocker recovery keys on Windows drives. Automate volume decryption logs, manage drive encryption states via command-line tools, and export secure configuration files directly to GitHub.
CVE-2026-45585MEDIUM19 Jul 2026
Windows BitLocker Security Feature Bypass Vulnerability
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMunder attack19 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-60137MEDIUMunder attack19 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC
Security vulnerability research writeups. CVE-2026-50402: Windows NTFS Elevation of Privilege (CVSS 7.8)
CVE-2026-50402HIGH19 Jul 2026
NTFS Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC1
sadsadsa
CVE-2026-66804HIGH19 Jul 2026
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVE-2026-56290CRITICAL19 Jul 2026
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RISK
open
GitHub PoC8
CVE-2026-63030 / CVE-2026-60137 - WordPress pre-auth RCE scanner
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC1
Unauthenticated Remote Code Execution (RCE) vulnerability in the JCE (Joomla Content Editor) extension for Joomla
CVE-2026-48907CRITICALunder attack19 Jul 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC2
CVE-2026-63030 / wp2shell
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out.
CVE-2026-3891CRITICAL19 Jul 2026
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC5
CVE-2026-46215 DRM GEM UAF Exploit for Linux 7.0 - The first working PoC for linux kernel 7 use after free- by Antonius (sw0rdm4n, w1sdom, ev1lut10n)
CVE-2026-46215HIGH19 Jul 2026
drm: Set old handle to NULL before prime swap in change_handle
41RISK
open
GitHub PoC3
PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC1
Exploit POC for Wp2Shell, CVE-2026-63030 + CVE-2026-63137
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
0xh7ml/CVE-2026-63030
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC2
CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated testing. Validates critical RCE vulnerability impact. For authorized security assessments only.
CVE-2026-33017CRITICALunder attack19 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
Defensive Windows security application providing compensating controls for CVE-2017-0144 (EternalBlue/MS17-010) through SMB monitoring, attack detection, automated firewall response, configuration auditing, and security reporting for legacy and unsupported systems.
CVE-2017-0144HIGHunder attackransomware19 Jul 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC10
wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation.
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
TomorrowX6/CVE-2026-63030-poc
CVE-2026-63030CRITICALunder attack19 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack19 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
previouspage 55 / 2,664next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.