Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,980cataloged exploits
36,899CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,476Referência 23,400GitHub PoC 15,250VulnCheck XDB 8,959Nuclei 4,393Metasploit 3,502✓ verified onlyrecentpopularrisk
79,980 exploits
GitHub PoC
Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization bypass / cross-label data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)
41RISK
open ↗GitHub PoC
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
76RISK
open ↗GitHub PoC
ctnBobong32/CVE-2026-43499-so-build
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 1
罗技云掌机 · GhostLock CVE-2026-43499 root 尝试
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 3
CvE-2026-43499偏移量计算
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC★ 1
A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Cxyofficial/x200-cve-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data destruction (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
41RISK
open ↗GitHub PoC
Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization
Metabase: Unsafe Deserialization of H2 Query Results
48RISK
open ↗GitHub PoC★ 47
Xiaomi K70e (duchamp) one-click root via CVE-2026-43499 (IonStack) + KernelSU integration
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read + delete of arbitrary documents (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
41RISK
open ↗GitHub PoC★ 12
CVE-2026-56164 EOP Exploit
Microsoft SharePoint Server Elevation of Privilege Vulnerability
68RISK
open ↗GitHub PoC
Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in 4.14.8/4.18.3/4.21.0)
Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query
41RISK
open ↗GitHub PoC
CVE-2026-15409 - Dectect
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open ↗GitHub PoC
The GREENDARK hospital infrastructure was configured by Dr. Gusto Rogue prior to his termination. No further details are provided.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗VulnCheck XDB
local
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
76RISK
open ↗GitHub PoC★ 1
Samsung libimagecodec.quram.so OOB Write PoC
Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote
41RISK
open ↗GitHub PoC
Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RISK
open ↗GitHub PoC★ 2
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RISK
open ↗GitHub PoC
NeseOS-Corp/CVE-2026-50657
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
33RISK
open ↗GitHub PoC★ 30
PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
Windows Narrator Braille Elevation of Privilege Vulnerability
41RISK
open ↗GitHub PoC★ 27
This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the websocket for file r/w and arbitrary code execution via RPC calls.
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RISK
open ↗VulnCheck XDB
initial-access
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary comman
60RISK
open ↗GitHub PoC
JohannesLks/CVE-2026-50338
Azure Spring Apps Elevation of Privilege Vulnerability
41RISK
open ↗VulnCheck XDB
initial-access
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
75RISK
open ↗GitHub PoC
Reproducer for CVE-2026-46457 — Apache Camel camel-nats inbound header injection (Camel control-header injection via a NATS publisher; CamelHttpUri -> SSRF)
Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers
41RISK
open ↗GitHub PoC★ 15
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open ↗GitHub PoC
Pen Tesing Lab exploiting VSFTPD 2.3.4 backdoor via Metasploit Framework
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.