Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
71,836 exploits
GitHub PoC
This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users without authentication process in flowise version 3.0.5 and lower due to token leakage.
CVE-2025-58434CRITICAL16 May 2026
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
75RISK
open
GitHub PoC2
Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG subsystem to achieve local privilege escalation (LPE) to root by safely corrupting a setuid binary directly in the shared Page Cache (RAM) without modifying files on disk
CVE-2026-31431HIGHunder attack16 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC
Maxime288/CVE-2026-31431-Copy-Fail-R-pertoire-de-Pr-vention
CVE-2026-31431HIGHunder attack16 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC1
CVE-2026-44578
CVE-2026-44578HIGH16 May 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open
GitHub PoC2
PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk multi-threaded scanning. Authorized testing & research only.
CVE-2026-6433HIGH16 May 2026
Custom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCE
56RISK
open
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL16 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL16 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
GitHub PoC
Safe Python scanner for CVE-2020-3452 (Cisco ASA/FTD WebVPN Directory Traversal)
CVE-2020-3452HIGHunder attack16 May 2026
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISK
open
GitHub PoC
Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.
CVE-2026-41940CRITICALunder attackransomware16 May 2026
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RISK
open
VulnCheck XDB
local
CVE-2026-43284HIGH16 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
Exploit for the CVE-2026-8181 - Burst Statistics WordPress Plugin Authentication Bypass
CVE-2026-8181CRITICAL16 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2025-59528CRITICAL16 May 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
GitHub PoC
CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.
CVE-2026-8181CRITICAL16 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
GitHub PoC7
CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.
CVE-2026-44578HIGH16 May 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL16 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
Read-only WordPress User Registration CVE-2026-1492 checker for hidden admins, plugin version, uploads PHP, cron, and compromise IOCs.
CVE-2026-1492CRITICAL16 May 2026
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
68RISK
open
VulnCheck XDB
local
CVE-2026-42897HIGHunder attack15 May 2026
Microsoft Exchange Server Spoofing Vulnerability
71RISK
open
VulnCheck XDB
initial-access
CVE-2026-8181CRITICAL15 May 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RISK
open
GitHub PoC3
In‑depth technical analysis of CVE‑2026‑41096, a critical heap overflow in Windows DNSAPI.dll enabling remote code execution via crafted DNS responses. Includes attack vectors, patch insights, and defensive guidance for security teams.
CVE-2026-41096CRITICAL15 May 2026
Windows DNS Client Remote Code Execution Vulnerability
48RISK
open
GitHub PoC
nhh9905/CVE-2022-37969
CVE-2022-37969HIGHunder attack15 May 2026
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RISK
open
GitHub PoC13
CVE-2026-46300
CVE-2026-46300HIGH15 May 2026
net: skbuff: preserve shared-frag marker during coalescing
41RISK
open
VulnCheck XDB
initial-access
CVE-2012-315315 May 2026
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RISK
open
VulnCheck XDB
initial-access
CVE-2026-0770CRITICALunder attack15 May 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
98RISK
open
VulnCheck XDB
local
CVE-2026-31431HIGHunder attack15 May 2026
crypto: algif_aead - Revert to operating out-of-place
100RISK
open
GitHub PoC75
NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF
CVE-2026-44578HIGH15 May 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open
VulnCheck XDB
local
CVE-2026-43284HIGH15 May 2026
xfrm: esp: avoid in-place decrypt on shared skb frags
78RISK
open
GitHub PoC
LangFlow RCE | CVE-2026-0770 | Proof-Of-Concept
CVE-2026-0770CRITICALunder attack15 May 2026
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
98RISK
open
VulnCheck XDB
initial-access
CVE-2026-42945CRITICAL15 May 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC6
Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and real-world scanning workflows. Includes references to the original NextSSRF research and exploit tooling.
CVE-2026-44578HIGH15 May 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open
GitHub PoC
tocong282/CVE-2026-44578-PoC
CVE-2026-44578HIGH15 May 2026
Next.js: Server-side request forgery in applications using WebSocket upgrades
68RISK
open
previouspage 63 / 2,395next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.