Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
14,997 exploits
GitHub PoC
kaleth4/CVE-2022-30190
CVE-2022-30190HIGHunder attackransomware14 Jun 2026
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISK
open
GitHub PoC1
CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool
CVE-2024-3094CRITICAL14 Jun 2026
Xz: malicious code in distributed source
70RISK
open
GitHub PoC
Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)
CVE-2026-42945CRITICAL14 Jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
CVE-2026-20127
CVE-2026-20127CRITICALunder attack14 Jun 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
100RISK
open
GitHub PoC2
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware14 Jun 2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC
CVE-2026-5513 — Bookly ≤ 27.2 Stored XSS via Cookie
CVE-2026-5513HIGH14 Jun 2026
Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie
41RISK
open
GitHub PoC
CVE-2026-20253 - Splunk Enterprise
CVE-2026-20253CRITICALunder attack14 Jun 2026
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RISK
open
GitHub PoC
CVE-2026-5513: Bookly <= 27.2 Stored XSS via Cookie (Unauthenticated)
CVE-2026-5513HIGH14 Jun 2026
Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie
41RISK
open
GitHub PoC
Apache HTTP Server 2.4.49 Path Traversal Vulnerability Reproduction
CVE-2021-41773HIGHunder attackransomware14 Jun 2026
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open
GitHub PoC
rohit-sundar/cve-2026-23744
CVE-2026-23744CRITICAL14 Jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC1
Defensive research notes for CVE-2026-5950, a BIND 9 resolver DoS vulnerability credited to Billy Baraja (BielraX).
CVE-2026-5950MEDIUM14 Jun 2026
Unbounded resend loop in BIND 9 resolver
33RISK
open
GitHub PoC
SQL Injection in Dagster database I/O managers via dynamic partition keys (DuckDB/Snowflake/BigQuery/DeltaLake) — High
CVE-2026-41490HIGH13 Jun 2026
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
41RISK
open
GitHub PoC
CyruxSec/CVE-2025-4524
CVE-2025-4524CRITICAL13 Jun 2026
Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion
68RISK
open
GitHub PoC
87achrafg-stack/CVE-2026-6279
CVE-2026-6279CRITICAL13 Jun 2026
Avada (Fusion) Builder <= 3.15.2 - Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via Widget AJAX Handler
48RISK
open
GitHub PoC
webshellseo8/CVE-2026-1555-POC
CVE-2026-1555CRITICAL13 Jun 2026
WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload
48RISK
open
GitHub PoC1
CVE-2026-45447
CVE-2026-45447HIGH13 Jun 2026
Heap Use-After-Free in the PKCS7_verify() Function
41RISK
open
GitHub PoC3
HTTP/2 Bomb (CVE-2026-49975) non-destructive vulnerability detector for Nginx / Apache httpd. Zero-dependency Python.
CVE-2026-49975HIGH13 Jun 2026
Apache HTTP Server: mod_http2 denial of service
53RISK
open
GitHub PoC
CyruxSec/CVE-2026-4524
CVE-2026-4524MEDIUM13 Jun 2026
Authentication Bypass Using an Alternate Path or Channel in GitLab
33RISK
open
GitHub PoC
87achrafg-stack/CVE-2026-48907
CVE-2026-48907CRITICALunder attack13 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.
CVE-2026-11417HIGH13 Jun 2026
OS Command Injection in NodejsFunction Bundling in aws-cdk-lib
41RISK
open
GitHub PoC1
(phpBB authentication bypass)
CVE-2026-48611CRITICAL13 Jun 2026
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
63RISK
open
GitHub PoC
CVE-2018-9276 — PRTG Network Monitor < 18.2.39 Authenticated RCE. For educational purposes and authorized penetration testing only.
CVE-2018-9276HIGHunder attack13 Jun 2026
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RISK
open
GitHub PoC
ExifTool RCE exploit (CVE-2021-22204) - improved version, no exiftool dependency
CVE-2021-22204MEDIUMunder attack13 Jun 2026
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open
GitHub PoC
CVE-2025-55182 exploit script
CVE-2025-55182CRITICALunder attackransomware13 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
PoC educacional do CVE-2021-4034, o PwnKit, LPE via pkexec do polkit. Uso autorizado apenas.
CVE-2021-4034HIGHunder attackransomware13 Jun 2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RISK
open
GitHub PoC1
Hunt-Benito/glinet-beryl-ax-triple-rce-cve-2026-11450-11451-11452-unauthenticated-root-on-travel-router
CVE-2026-11450MEDIUM13 Jun 2026
GL.iNet GL-MT3000 Path Normalization dlopen command injection
33RISK
open
GitHub PoC
Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)
CVE-2024-3094CRITICAL13 Jun 2026
Xz: malicious code in distributed source
70RISK
open
GitHub PoC5
CVE-2026-20253
CVE-2026-20253CRITICALunder attack13 Jun 2026
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
100RISK
open
GitHub PoC
JupyterHub XSRF bypass via cross-origin form POST (Sec-Fetch-Mode: no-cors) — CWE-352
CVE-2026-40864MEDIUM13 Jun 2026
JupyterHub: Cross-origin form POSTs bypass XSRF
33RISK
open
GitHub PoC
rootdirective-sec/CVE-2026-42647-Lab
CVE-2026-42647CRITICAL13 Jun 2026
WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability
63RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.