Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
14,997 exploits
GitHub PoC★ 4
CVE-2026-49772 — The Events Calendar (WordPress) unauthenticated blind SQLi PoC
WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability
48RISK
open ↗GitHub PoC
Vulnerability proof of concept reworked from https://github.com/utmost3/cve/issues/2 I take no credit for discovering the vulnerability. This is for educational and portfolio purposes only.
Linksys MR9600 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus os command injection
41RISK
open ↗GitHub PoC★ 81
Proof of Concept (PoC) demonstrating the CVE-2026-18220, an out-of-bounds (OOB) write vulnerability in the DLX ELF backend of GNU binutils (specifically triggered via `objdump -g`)
Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing
41RISK
open ↗GitHub PoC★ 1
Technical analysis of CVE-2026-42945 (NGINX Rift), a critical heap buffer overflow in NGINX's rewrite engine caused by a state mismatch between length calculation and copy operations, enabling worker crashes and potential remote code execution.
NGINX ngx_http_rewrite_module vulnerability
60RISK
open ↗GitHub PoC★ 1
El exploit para obtener root usado la vulnerabilidad del CVE-2021-4034 o tambien llamado PwnKit el cual permite teniendo un shell hacer una escalada de privilegios siempre y cuando la version de pkexec sea = o < que la v0.105
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open ↗GitHub PoC★ 1
sec0x/CVE-2026-48907
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open ↗GitHub PoC
Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RISK
open ↗GitHub PoC
Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
33RISK
open ↗GitHub PoC★ 3
CVE-2025-48907 - Unauthenticated RCE exploit for Joomla JCE < 2.9.99.5
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open ↗GitHub PoC★ 2
Technical analysis of CVE-2026-46300 (Fragnesia), a Linux kernel page-cache write vulnerability that enables local privilege escalation through SKBFL_SHARED_FRAG invariant violations in the networking stack.
net: skbuff: preserve shared-frag marker during coalescing
56RISK
open ↗GitHub PoC
React2Shell POC
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open ↗GitHub PoC
CVE-2026-4020 - Draft
Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API
68RISK
open ↗GitHub PoC★ 16
Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarded. Authorized testing only.
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open ↗GitHub PoC
POC for CVE-2026-23744 for a python revshell
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open ↗GitHub PoC
CVE-2026-39031 — offline plaintext password recovery for Lansweeper lsrunase 2.0 / lsencrypt 2.0 via a hardcoded RC4 key. PoC + technical advisory.
Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt crede
33RISK
open ↗GitHub PoC★ 7
Unauthenticated PHP Object Injection to RCE in WP Activity Log <= 5.6.3.1 (CVE-2026-54806)
WordPress WP Activity Log plugin <= 5.6.3.1 - PHP Object Injection vulnerability
48RISK
open ↗GitHub PoC★ 1
Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
48RISK
open ↗GitHub PoC
GNN-based supply chain backdoor detector for Python packages. Uses Code Property Graphs + 3-layer GCN to detect obfuscated backdoors by learning semantic data flow patterns — not just signatures. Inspired by XZ Utils (CVE-2024-3094).
Xz: malicious code in distributed source
70RISK
open ↗GitHub PoC
Chaelsoo/CVE-2022-23131-Wrappers
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RISK
open ↗GitHub PoC
POC for CVE-2026-21858
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open ↗GitHub PoC
Technical analysis of CVE-2025-68613, a critical Expression Injection vulnerability in n8n that allows authenticated attackers to achieve Remote Code Execution (RCE)
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open ↗GitHub PoC
Luisbuilds-data/cve-2024-1086-writeup
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open ↗GitHub PoC
POC for CVE-2025-32463
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RISK
open ↗GitHub PoC★ 23
CVE-2026-48909 PoC
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RISK
open ↗GitHub PoC
Version: Download Manager 3.3.5.2 Title: Missing Authorization - Unauthenticated IDOR Exploit
WordPress Download Manager plugin <= 3.3.52 - Broken Access Control vulnerability
33RISK
open ↗GitHub PoC
POC for CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open ↗GitHub PoC
xxconi/CVE-2026-49777-CVE-2026-10735
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.