Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,760cataloged exploits
32,083CVEs with public exploitation
1,932lab-tested
71,760 exploits
GitHub PoC2
CVE-2026-9082 | SA-CORE-2026-004
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
cve poc
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC2
Langflow Arbitrary Directory Deletion
CVE-2026-42048CRITICAL21 May 2026
Langflow: Path Traversal in Langflow Knowledge Bases API
48RISK
open
GitHub PoC1
CVE-2026-9082
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
A Go implementation of dirtydecrypt (CVE-2026-31635)
CVE-2026-31635HIGH21 May 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
CVE-2026-46680 exploit
CVE-2026-46680HIGH21 May 2026
containerd user ID handling bypass allows runAsNonRoot evasion
41RISK
open
GitHub PoC1
More portable POC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux
CVE-2026-31431HIGHunder attack21 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC4
PoC for CVE-2024-6678
CVE-2024-6678CRITICAL21 May 2026
Authentication Bypass by Spoofing in GitLab
48RISK
open
GitHub PoC
CVE-2026-0300 PAN-OS 12.1, 11.2, 11.1, 10.2
CVE-2026-0300CRITICALunder attack21 May 2026
PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
90RISK
open
GitHub PoC
CVE-2026-31431-CopyFail---Minified-LPE-PoC
CVE-2026-31431HIGHunder attack21 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
Exploit-DB
FUXA 1.2.9 - RCE
CVE-2026-25895CRITICAL21 May 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
48RISK
open
GitHub PoC1
PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC11
CVE-2026-41091
CVE-2026-41091HIGHunder attack21 May 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC20
Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module on PostgreSQL-backed sites.
CVE-2026-9082CRITICALunder attack21 May 2026
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
100RISK
open
GitHub PoC
EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps
CVE-2013-181421 May 2026
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RISK
open
GitHub PoC
「🪶」PoC (Proof of concept) of Path traversal + RCE in Apache HTTP Server 2.4.49
CVE-2021-41773HIGHunder attackransomware21 May 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC1
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload → RCE
CVE-2026-4885CRITICAL21 May 2026
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload
48RISK
open
GitHub PoC
CVE-2026-45829
CVE-2026-45829CRITICAL21 May 2026
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RISK
open
GitHub PoC
Scanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.
CVE-2024-6387HIGH21 May 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RISK
open
GitHub PoC
Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and edit code injection fields.
CVE-2026-26980CRITICAL20 May 2026
Ghost has a SQL Injection in its Content API
75RISK
open
GitHub PoC
gitgudKrish/cve-2025-29927-nextjs
CVE-2025-29927CRITICAL20 May 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
MGTx2/CVE-2026-39107
CVE-2026-39107MEDIUM20 May 2026
A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails
33RISK
open
GitHub PoC1
CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner for authorized testing.
CVE-2026-2587CRITICAL20 May 2026
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used
48RISK
open
GitHub PoC
fevar54/FULL-ANALYSIS---CVE-2026-45829-ChromaDB-
CVE-2026-45829CRITICAL20 May 2026
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un
53RISK
open
GitHub PoC
julianertle/CVE-2023-0386-CTF
CVE-2023-0386HIGHunder attack20 May 2026
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities wa
86RISK
open
GitHub PoC
Exploit for DirtyDecrypt - CVE-2026-31635 Local Privilege Escalation
CVE-2026-31635HIGH20 May 2026
rxrpc: fix oversized RESPONSE authenticator length check
41RISK
open
GitHub PoC
A Go implementation of dirtyfrag (CVE-2026-43284 / CVE-2026-43500)
CVE-2026-43284HIGH20 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-42271HIGHunder attack20 May 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RISK
open
previouspage 56 / 2,392next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.