Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,910GitHub PoC 14,997VulnCheck XDB 8,843Nuclei 4,358Metasploit 3,489✓ verified onlyrecentpopularrisk
14,997 exploits
GitHub PoC
CVE-2026-7515: BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion TO RCE EXPLOİT
BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
48RISK
open ↗GitHub PoC★ 1
Unauthenticated Privilege Escalation via Account Takeover
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RISK
open ↗GitHub PoC
Saku0512/CVE-2026-54761-poc
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
33RISK
open ↗GitHub PoC★ 6
PoC exploit for CVE-2023-6019 - Remote Code Execution via unauthenticated Ray Dashboard Jobs API.
Ray Command Injection in cpu_profile Parameter
85RISK
open ↗GitHub PoC
PoC for CVE-2022-0543 – Redis Remote Code Execution (RCE)
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RISK
open ↗GitHub PoC
CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
48RISK
open ↗GitHub PoC
Повышение привилегий через race condition в polkit
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RISK
open ↗GitHub PoC★ 3
CVE-2026-10520 - CVE-2026-10523 - Ivanti Sentry
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow
60RISK
open ↗GitHub PoC
AlexMihailEngineer/CVE-2026-11784-Optimole-CSRF
Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action
33RISK
open ↗GitHub PoC★ 2
ptd200110/CVE-2024-27198-SOC-Lab
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
100RISK
open ↗GitHub PoC
CVE-2026-42055 - Draft
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
48RISK
open ↗GitHub PoC
xxconi/CVE-2026-4782
Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter
33RISK
open ↗GitHub PoC★ 4
Detection scripts, patch checker & hardening guide for CVE-2026-44963 (Veeam B&R RCE)
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
48RISK
open ↗GitHub PoC
PoC de CVE-2026-54420: explotacion via symlink en el plugin LiteSpeed de cPanel/WHM.
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provide
71RISK
open ↗GitHub PoC
Defensive lab validation and SOC detection guidance for CVE-2026-48907 in Joomla JCE <= 2.9.99.4, including Apache/Joomla/auditd telemetry, webshell artifacts, Sigma rules, MITRE ATT&CK mapping and mitigation recommendations.
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open ↗GitHub PoC
Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RISK
open ↗GitHub PoC★ 2
CVE-2025-54123 Hoverfly Command Injection to RCE PoC
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
68RISK
open ↗GitHub PoC
Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
100RISK
open ↗GitHub PoC★ 1
Unauthenticated RCE exploit for Veritas Backup Exec Agent (CVE-2021-27876/77/78) — SHA auth bypass to SYSTEM via NDMP
An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc
91RISK
open ↗GitHub PoC★ 1
CVE-2026-38165 (SSTI)
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2
48RISK
open ↗GitHub PoC★ 1
Defensive lab validation and SOC detection guidance for CVE-2026-48907 in Joomla JCE <= 2.9.99.4, including Apache/Joomla/auditd telemetry, webshell artifacts, Sigma rules, MITRE ATT&CK mapping and mitigation recommendations.
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open ↗GitHub PoC
Authenticated Remote Code Execution via loadReader functionName code injection in DbGate
DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
63RISK
open ↗GitHub PoC★ 1
A web version of the bash scripts wrote for Check Point CVE-2026-50751 and CVE-2026-50752. This uses a local server to scan and make changes using Check Point Web API
User Authentication Bypass in VPN Remote Access and Mobile Access
100RISK
open ↗GitHub PoC★ 11
0xCyberstan/CVE-2026-46215-POC
drm: Set old handle to NULL before prime swap in change_handle
41RISK
open ↗GitHub PoC
A local lab for studying, reproducing, and verifying the patch for CVE-2026-42208: an unauthenticated SQL injection in LiteLLM's API key authentication path.
LiteLLM: SQL injection in Proxy API key verification
100RISK
open ↗GitHub PoC
CVE-2025-6254 — Doctreat Core <= 1.6.8 — Unauthenticated Privilege Escalation
Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation
48RISK
open ↗GitHub PoC
Root-Level RCE via OS Command Injection in Ivanti Sentry
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
85RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.