Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,912cataloged exploits
36,852CVEs with public exploitation
24,695lab-tested
79,904 exploits
GitHub PoC6
wp2shell - WordPress CVE-2026-63030 Exploit & Scanner
CVE-2026-63030CRITICALunder attack18 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Advisory for CVE-2026-51385. Needed to publish it as GRAPHIFY hasnt recognized the advisory neither publish it, and MITRE assigned CVE-2026-51385, this is the advisory for it.
CVE-2026-51385MEDIUM18 Jul 2026
An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code v
33RISK
open
GitHub PoC1
CVE-2021-3129: Laravel Debug Mode RCE - Complete exploitation lab with Python exploit, Docker container, and security analysis guide.
CVE-2021-3129CRITICALunder attackransomware18 Jul 2026
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISK
open
GitHub PoC1
Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. Developed by Ebrahim Shafiei (EbraSha) for vulnerability assessment, security research, and authorized penetration testing.
CVE-2026-60137MEDIUMunder attack18 Jul 2026
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
100RISK
open
GitHub PoC
tcyph3r/wp2shell-cve-2026-63030-root-cause
CVE-2026-63030CRITICALunder attack18 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.
CVE-2026-63030CRITICALunder attack18 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC1
PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution.
CVE-2026-46420MEDIUM18 Jul 2026
setup-php: Command Injection in Repository-Derived PHP Version Resolution
33RISK
open
GitHub PoC8
CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)
CVE-2026-63030CRITICALunder attack18 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
fancyzll/CVE-2026-43499_OPPO-MT6835
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC2
2932796375github/CVE-2026-43499_OPPO-MT6835
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
TM4Web Vulnerability - CVE-2022-35499
CVE-2022-35499HIGH17 Jul 2026
In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via inject
41RISK
open
GitHub PoC
TM4WEB Vulnerability - CVE-2022-35497
CVE-2022-3549717 Jul 2026
In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid se
23RISK
open
GitHub PoC
Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH
CVE-2007-244717 Jul 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC5
CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework 🔥 SSRF→Erlang RPC→RCE→root privesc. Features: --detect safe check, --exec, --read-file, --privesc, --rpc, interactive shell, batch threading, file write, ws-url override, pipe support.🛡️ KEV listed CVSS 10.0 actively exploited. Authorized testing only. Use Ethically, Stay Legal. 🔒
CVE-2026-15409CRITICALunder attackransomware17 Jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open
GitHub PoC1
WordPress KeepInMind CVE-2026-9271 Exploit - Tool detecting stored XSS in KeepInMind plugin v0.8.4.2 and below. Built by Sudeepa Wanigarathna, it simulates CSS injection to hijack admin accounts. Features safe testing, attack simulation, credential capture, bulk scanning, reporting. Essential for security researchers.
CVE-2026-9271MEDIUM17 Jul 2026
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
33RISK
open
GitHub PoC
Python port of the CVE-2023-23752 exploit — Joomla! < 4.2.8 unauthenticated information disclosure (user list + DB credentials leak)
CVE-2023-23752MEDIUMunder attack17 Jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack17 Jul 2026
File overwrite in file update API in Gogs
100RISK
open
GitHub PoC7
CVE-2026-63030
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC6
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! 🛡️🔒
CVE-2021-36260CRITICALunder attack17 Jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC1
bekwiner/cve-2026-47777
CVE-2026-47777HIGH17 Jul 2026
Mastodon has a consent-check bypass in its remote Collections
41RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack17 Jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
VulnCheck XDB
info-leak
CVE-2023-23752MEDIUMunder attack17 Jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48203CRITICAL17 Jul 2026
Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
48RISK
open
GitHub PoC
Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE via camel-exec) through CXF-RS/CXF-SOAP/Knative endpoints (fixed in 4.14.6/4.18.2/4.19.0)
CVE-2026-47323CRITICAL17 Jul 2026
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
48RISK
open
GitHub PoC
tungduongNT/CVE-2014-0160.
CVE-2014-0160HIGHunder attack17 Jul 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC63
CVE-2026-63030, CVE-2026-60137, wp2shell scanner
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC6
sorrow404Null/CVE-2026-43499-RMX5200
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-38526 Exploit | by infrar3d
CVE-2026-38526CRITICAL17 Jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
previouspage 59 / 2,664next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.