Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,963cataloged exploits
36,896CVEs with public exploitation
24,695lab-tested
79,963 exploits
GitHub PoC
hg0434hongzh0/CVE-2026-14266
CVE-2026-14266HIGH17 Jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
tungduongNT/CVE-2014-0160.
CVE-2014-0160HIGHunder attack17 Jul 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC63
CVE-2026-63030, CVE-2026-60137, wp2shell scanner
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH
CVE-2007-244717 Jul 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack17 Jul 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2021-36260CRITICALunder attack17 Jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC773
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC6
sorrow404Null/CVE-2026-43499-RMX5200
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC865
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC5
CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework 🔥 SSRF→Erlang RPC→RCE→root privesc. Features: --detect safe check, --exec, --read-file, --privesc, --rpc, interactive shell, batch threading, file write, ws-url override, pipe support.🛡️ KEV listed CVSS 10.0 actively exploited. Authorized testing only. Use Ethically, Stay Legal. 🔒
CVE-2026-15409CRITICALunder attackransomware17 Jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open
GitHub PoC
TM4WEB Vulnerability - CVE-2022-35497
CVE-2022-3549717 Jul 2026
In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid se
23RISK
open
GitHub PoC1
WordPress KeepInMind CVE-2026-9271 Exploit - Tool detecting stored XSS in KeepInMind plugin v0.8.4.2 and below. Built by Sudeepa Wanigarathna, it simulates CSS injection to hijack admin accounts. Features safe testing, attack simulation, credential capture, bulk scanning, reporting. Essential for security researchers.
CVE-2026-9271MEDIUM17 Jul 2026
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
33RISK
open
GitHub PoC
TM4Web Vulnerability - CVE-2022-35499
CVE-2022-35499HIGH17 Jul 2026
In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via inject
41RISK
open
GitHub PoC
fancyzll/CVE-2026-43499_OPPO-MT6835
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE via camel-exec) through CXF-RS/CXF-SOAP/Knative endpoints (fixed in 4.14.6/4.18.2/4.19.0)
CVE-2026-47323CRITICAL17 Jul 2026
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
48RISK
open
VulnCheck XDB
info-leak
CVE-2023-23752MEDIUMunder attack17 Jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC46
CVE-2026-50416: Windows 11 KASLR bypass
CVE-2026-50416LOW17 Jul 2026
Win32k Information Disclosure Vulnerability
28RISK
open
GitHub PoC7
CVE-2026-63030
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Reproducer for CVE-2026-48204: Apache Camel camel-mongodb-gridfs gridfs.* header injection overriding the GridFS operation (enumerate/read/delete files) from an unauthenticated HTTP request (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48204CRITICAL17 Jul 2026
Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration
48RISK
open
GitHub PoC1
Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via DNS) and enabling internal-hostname reconnaissance (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48205CRITICAL17 Jul 2026
Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
48RISK
open
GitHub PoC
jaf0rk/CVE-2026-14431
CVE-2026-14431HIGH17 Jul 2026
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside
41RISK
open
GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.
CVE-2026-15583HIGH17 Jul 2026
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
41RISK
open
GitHub PoC1
MiaPatsune/cve-2026-43499
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC6
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! 🛡️🔒
CVE-2021-36260CRITICALunder attack17 Jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC1
bekwiner/cve-2026-47777
CVE-2026-47777HIGH17 Jul 2026
Mastodon has a consent-check bypass in its remote Collections
41RISK
open
GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-46442 for authorized security research.
CVE-2026-46442CRITICAL17 Jul 2026
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
75RISK
open
GitHub PoC
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48203CRITICAL17 Jul 2026
Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
48RISK
open
GitHub PoC1
CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution. No dependencies.
CVE-2026-55579CRITICAL17 Jul 2026
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
48RISK
open
previouspage 60 / 2,666next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.