Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,979cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
79,979 exploits
GitHub PoC7
CVE-2026-63030
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC
Reproducer for CVE-2026-48204: Apache Camel camel-mongodb-gridfs gridfs.* header injection overriding the GridFS operation (enumerate/read/delete files) from an unauthenticated HTTP request (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48204CRITICAL17 Jul 2026
Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration
48RISK
open
GitHub PoC1
MiaPatsune/cve-2026-43499
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC2
2932796375github/CVE-2026-43499_OPPO-MT6835
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH
CVE-2007-244717 Jul 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
fancyzll/CVE-2026-43499_OPPO-MT6835
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Python port of the CVE-2023-23752 exploit — Joomla! < 4.2.8 unauthenticated information disclosure (user list + DB credentials leak)
CVE-2023-23752MEDIUMunder attack17 Jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC865
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
WordPress KeepInMind CVE-2026-9271 Exploit - Tool detecting stored XSS in KeepInMind plugin v0.8.4.2 and below. Built by Sudeepa Wanigarathna, it simulates CSS injection to hijack admin accounts. Features safe testing, attack simulation, credential capture, bulk scanning, reporting. Essential for security researchers.
CVE-2026-9271MEDIUM17 Jul 2026
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
33RISK
open
GitHub PoC
CVE-2026-38526 Exploit | by infrar3d
CVE-2026-38526CRITICAL17 Jul 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RISK
open
GitHub PoC6
sorrow404Null/CVE-2026-43499-RMX5200
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
tungduongNT/CVE-2014-0160.
CVE-2014-0160HIGHunder attack17 Jul 2026
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISK
open
GitHub PoC
Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE via camel-exec) through CXF-RS/CXF-SOAP/Knative endpoints (fixed in 4.14.6/4.18.2/4.19.0)
CVE-2026-47323CRITICAL17 Jul 2026
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
48RISK
open
VulnCheck XDB
initial-access
CVE-2026-63030CRITICALunder attack17 Jul 2026
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
100RISK
open
GitHub PoC5
CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework 🔥 SSRF→Erlang RPC→RCE→root privesc. Features: --detect safe check, --exec, --read-file, --privesc, --rpc, interactive shell, batch threading, file write, ws-url override, pipe support.🛡️ KEV listed CVSS 10.0 actively exploited. Authorized testing only. Use Ethically, Stay Legal. 🔒
CVE-2026-15409CRITICALunder attackransomware17 Jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open
VulnCheck XDB
info-leak
CVE-2023-23752MEDIUMunder attack17 Jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC
hg0434hongzh0/CVE-2026-14266
CVE-2026-14266HIGH17 Jul 2026
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
41RISK
open
GitHub PoC1
bekwiner/cve-2026-47777
CVE-2026-47777HIGH17 Jul 2026
Mastodon has a consent-check bypass in its remote Collections
41RISK
open
GitHub PoC
Sana-404/CVE-2026-8388-Mitigation-and-Detection
CVE-2026-8388MEDIUM16 Jul 2026
Incorrect boundary conditions in the JavaScript Engine: JIT component
33RISK
open
VulnCheck XDB
initial-access
CVE-2026-20896CRITICAL16 Jul 2026
Gitea Docker image trusts spoofable reverse-proxy headers by default
63RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-8110HIGHunder attack16 Jul 2026
File overwrite in file update API in Gogs
100RISK
open
VulnCheck XDB
initial-access
CVE-2024-25600CRITICAL16 Jul 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-55182CRITICALunder attackransomware16 Jul 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-33017CRITICALunder attack16 Jul 2026
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RISK
open
GitHub PoC
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware16 Jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC40
Standalone CVE-2026-43499 PoC for Galaxy S25 Ultra SM-S938N S938NKSUACZF1
CVE-2026-43499HIGH16 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse shells, file upload/download, async scanning, stealth mode, proxy support, and multi-threaded vulnerability scanning. For authorized security testing only.
CVE-2024-25600CRITICAL16 Jul 2026
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RISK
open
GitHub PoC
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
CVE-2026-43499HIGH16 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF bypass, reverse shell, SQLMap integration, Burp extension generation, and reporting for penetration testing and security research.
CVE-2026-3180HIGH16 Jul 2026
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
41RISK
open
GitHub PoC
uname1able/CVE-2025-21333
CVE-2025-21333HIGHunder attack16 Jul 2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
previouspage 61 / 2,666next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.