Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
14,997 exploits
GitHub PoC
webshellseo8/CVE-2026-48908-POC
CVE-2026-48908CRITICAL21 Jun 2026
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
68RISK
open
GitHub PoC1
Modern Joomla Auth-attack Toolkit J3 / J4 / J5 - CVE-2023-23752 · CVE-2023-23755 · CVE-2025-25227
CVE-2023-23752MEDIUMunder attack21 Jun 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
POC for CVE-2025-24054
CVE-2025-24054MEDIUMunder attack21 Jun 2026
NTLM Hash Disclosure Spoofing Vulnerability
75RISK
open
GitHub PoC
xxconi/CVE-2026-49777-CVE-2026-10735
CVE-2026-49777CRITICAL21 Jun 2026
WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability
63RISK
open
GitHub PoC5
CVE-2026-47729
CVE-2026-47729MEDIUM21 Jun 2026
Squid: Memory disclosure in FTP gateway
33RISK
open
GitHub PoC23
CVE-2026-48909 PoC
CVE-2026-48909CRITICAL21 Jun 2026
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RISK
open
GitHub PoC
POC for CVE-2025-55182
CVE-2025-55182CRITICALunder attackransomware21 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
POC for CVE-2026-21858
CVE-2026-21858CRITICAL21 Jun 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
85RISK
open
GitHub PoC
POC for CVE-2025-24071
CVE-2025-24071MEDIUM21 Jun 2026
Microsoft Windows File Explorer Spoofing Vulnerability
38RISK
open
GitHub PoC
POC for CVE-2025-48384
CVE-2025-48384HIGHunder attack21 Jun 2026
Git allows arbitrary code execution through broken config quoting
71RISK
open
GitHub PoC1
Nuclei template for CVE-2026-11561 — Apinizer SSTI / RCE version detection
CVE-2026-11561CRITICAL21 Jun 2026
SSTI in Soagen Informatics' Apinizer
48RISK
open
GitHub PoC
POC for CVE-2025-24893
CVE-2025-24893CRITICALunder attack21 Jun 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC
Luisbuilds-data/cve-2024-1086-writeup
CVE-2024-1086HIGHunder attackransomware21 Jun 2026
Use-after-free in Linux kernel's netfilter: nf_tables component
76RISK
open
GitHub PoC
Full compromise of TryHackMe's Ice machine — Icecast 2.0.1 RCE (CVE-2004-1561) via buffer overflow, followed by Windows privilege escalation through UAC bypass / COM hijacking. Includes detailed methodology and remediation.
CVE-2004-156121 Jun 2026
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISK
open
GitHub PoC
POC for CVE-2025-29927
CVE-2025-29927CRITICAL21 Jun 2026
Authorization Bypass in Next.js Middleware
85RISK
open
GitHub PoC
Traveller is an Easy Linux machine featuring a Joomla 4.2.7 travel booking website vulnerable to CVE-2023-23752, an unauthenticated REST API information disclosure that leaks database credentials, leading to admin panel access, remote code execution, and root via sudo misconfiguration.
CVE-2023-23752MEDIUMunder attack21 Jun 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
Hunt-Benito/ash-authentication-oauth2-oidc-account-takeover-cve-2026-49757-email-based-user-matching
CVE-2026-49757CRITICAL21 Jun 2026
OAuth2/OIDC account takeover in AshAuthentication via email-based user matching
48RISK
open
GitHub PoC3
CVE-2026-41091 RedSun | Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM 🔥 via Cloud Files API + NTFS junction trickery. Forces Defender to write malicious payloads to System32 with SYSTEM rights. ⚠️ Actively exploited in wild. CVSS 7.8. Patch: Defender Engine 1.1.26040.8. 🛡️ Educational PoC only.
CVE-2026-41091HIGHunder attack20 Jun 2026
Microsoft Defender Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC2
Missing Authorization to Unauthenticated File Modification
CVE-2026-11912HIGH20 Jun 2026
Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
41RISK
open
GitHub PoC2
CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0.
CVE-2026-37149HIGH20 Jun 2026
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil
41RISK
open
GitHub PoC
aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation
CVE-2023-46604CRITICALunder attackransomware20 Jun 2026
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RISK
open
GitHub PoC
ClearLotus-git/CVE-2026-4480-PoC
CVE-2026-4480CRITICAL20 Jun 2026
Samba: samba: remote code execution in printing subsystem via unescaped job description
68RISK
open
GitHub PoC1
GadaLuBau1337/CVE-2026-44578
CVE-2026-44578HIGH20 Jun 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open
GitHub PoC
HTTP/2 Bomb (CVE-2026-49975) non-destructive vulnerability detector for Nginx / Apache httpd. Zero-dependency Python.
CVE-2026-49975HIGH20 Jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISK
open
GitHub PoC
Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053
CVE-2019-905320 Jun 2026
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RISK
open
GitHub PoC
Technical analysis of Apache Tomcat CVE-2024-50379, covering root cause, exploitation conditions, detection strategies, and mitigation techniques.
CVE-2024-50379CRITICAL20 Jun 2026
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
60RISK
open
GitHub PoC1
Unauthenticated Privilege Escalation via Account Takeover
CVE-2026-11551CRITICAL19 Jun 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RISK
open
GitHub PoC
Exploitability PoC for CVE-2026-43515 (Apache Tomcat constraint bypass).
CVE-2026-43515CRITICAL19 Jun 2026
Apache Tomcat: Security constraints not correctly applied
48RISK
open
GitHub PoC3
CVE-2026-42530
CVE-2026-42530CRITICAL19 Jun 2026
NGINX Open-Source ngx_http_v3_module vulnerability
48RISK
open
GitHub PoC
CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover
CVE-2026-11551CRITICAL19 Jun 2026
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.