Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
14,946 exploits
GitHub PoC
CVE-2022-36804 Bitbucket command execution and file transfer tool
CVE-2022-36804HIGHunder attack21 Aug 2026
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RISK
open
GitHub PoC
Stored XSS via User-Agent in Admin Order View in PhocaCart
CVE-2026-76564HIGH21 Aug 2026
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
41RISK
open
GitHub PoC
PoC for J2Store CVE-2026-67358–67362 (J2Commerce security advisory Aug 2026)
CVE-2026-67358MEDIUM21 Aug 2026
Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
33RISK
open
GitHub PoC
CVE-2026-39113: SQLite SQLAR heap-buffer-overflow advisory and reproducer
CVE-2026-3911321 Aug 2026
Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3a
23RISK
open
GitHub PoC1
PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.
CVE-2026-58455CRITICAL21 Aug 2026
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
63RISK
open
GitHub PoC
Reflected XSS via price_from & price_to Filter Parameters in PhocaCart
CVE-2026-76565MEDIUM21 Aug 2026
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
33RISK
open
GitHub PoC1
Educational use only!
CVE-2026-64638HIGH21 Aug 2026
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
68RISK
open
GitHub PoC
JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.
CVE-2026-48907CRITICALunder attack21 Aug 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
CVE-2026-41567 1day
CVE-2026-41567HIGH21 Aug 2026
Docker: `PUT /containers/{id}/archive` executes container binary on the host
41RISK
open
GitHub PoC1
elkhaoudari/CVE-2018-7600-PoC
CVE-2018-7600CRITICALunder attackransomware20 Aug 2026
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISK
open
GitHub PoC
aarch64 race condition checker
CVE-2026-46242HIGH20 Aug 2026
eventpoll: fix ep_remove struct eventpoll / struct file UAF
41RISK
open
GitHub PoC
Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover
CVE-2026-18315CRITICAL20 Aug 2026
TrueBooker <= 1.2.6 - Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover to 'truebooker_wp_user_id' Parameter
48RISK
open
GitHub PoC
Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts. Measurement, not certification.
CVE-2026-24301HIGH20 Aug 2026
Microsoft Copilot Information Disclosure Vulnerability
41RISK
open
GitHub PoC
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
CVE-2010-207520 Aug 2026
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISK
open
GitHub PoC
Analyze and reproduce CVE-2025-55182.
CVE-2025-55182CRITICALunder attackransomware20 Aug 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC14
Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database
CVE-2026-18963CRITICAL20 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC
CVE-2026-19478: GitLab GraphQL Vulnerability PoC
CVE-2026-19478CRITICAL20 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC
CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).
CVE-2026-18366CRITICAL20 Aug 2026
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
48RISK
open
GitHub PoC
Hunt-Benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt
CVE-2026-71960CRITICAL20 Aug 2026
Cudy WR3000 2.0 Hard-coded JWT Secret Authentication Bypass via MQTT
48RISK
open
GitHub PoC
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
CVE-2026-63030CRITICALunder attack20 Aug 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC35
Exploit for KeyCloak CVE-2026-18963
CVE-2026-18963CRITICAL20 Aug 2026
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
63RISK
open
GitHub PoC1
Safely detect Citrix NetScaler CVE-2026-8452
CVE-2026-8452HIGHunder attack20 Aug 2026
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
71RISK
open
GitHub PoC
Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.
CVE-2026-19598CRITICAL19 Aug 2026
Pods <= 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router
63RISK
open
GitHub PoC
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
CVE-2026-15748CRITICAL19 Aug 2026
Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
48RISK
open
GitHub PoC
MattiaCervelli/CVE-2025-24893_Analysis
CVE-2025-24893CRITICALunder attack19 Aug 2026
Remote code execution as guest via SolrSearchMacros request in xwiki
100RISK
open
GitHub PoC1
renzi25031469/CVE-2026-19478
CVE-2026-19478CRITICAL19 Aug 2026
Improper Control of Generation of Code ('Code Injection') in GitLab
63RISK
open
GitHub PoC
CVE-2026-73072 - Draft or TODO
CVE-2026-73072HIGH19 Aug 2026
Vim: Heap Buffer Overflow when Loading a Spell File
41RISK
open
GitHub PoC
fastjson jsontype利用
CVE-2026-16723CRITICAL19 Aug 2026
Remote Code Execution in fastjson 1.2.68–1.2.83
53RISK
open
GitHub PoC
andreamammano89-maker/CVE-2021-42013_821311
CVE-2021-42013CRITICALunder attackransomware19 Aug 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC1
VsockDrop (CVE-2026-53365) Linux kernel io_uring zerocopy vsock LPE exploit mirror — MaherAzzouzi, MIT; for authorized security testing
CVE-2026-53365HIGH19 Aug 2026
vsock/virtio: fix zerocopy completion for multi-skb sends
41RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.