Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
14,997 exploits
GitHub PoC1
PoC de CVE-2025-48595: desbordamiento de entero en multiples ubicaciones del Framework de Android.
CVE-2025-48595HIGHunder attack09 Jun 2026
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
71RISK
open
GitHub PoC
fevar54/CVE-2024-21182---Oracle-WebLogic-Server-JNDI-Injection-RCE
CVE-2024-21182HIGHunder attack09 Jun 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
93RISK
open
GitHub PoC
jenniferreire26/CVE-2026-0257
CVE-2026-0257HIGHunder attackransomware09 Jun 2026
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
100RISK
open
GitHub PoC
CVE-2026-42271 - Draft
CVE-2026-42271HIGHunder attack09 Jun 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
100RISK
open
GitHub PoC
CVE-2026-45067 - Draft
CVE-2026-45067MEDIUM09 Jun 2026
Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
33RISK
open
GitHub PoC
Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).
CVE-2026-47429CRITICAL09 Jun 2026
Vitest: Arbitrary file can be read and executed when Vitest UI server is listening
48RISK
open
GitHub PoC
rootdirective-sec/CVE-2025-11262-Lab
CVE-2025-11262HIGH09 Jun 2026
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
41RISK
open
GitHub PoC1
I created simple react2shell CVE-2025-55182 python exploit
CVE-2025-55182CRITICALunder attackransomware09 Jun 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC1
Insert PHP Plugin PHP Code Injection
CVE-2017-20251CRITICAL09 Jun 2026
WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
48RISK
open
GitHub PoC
jenniferreire26/CVE-2026-42945
CVE-2026-42945CRITICAL09 Jun 2026
NGINX ngx_http_rewrite_module vulnerability
60RISK
open
GitHub PoC
Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque até RCE e miniguia de hardening
CVE-2024-42327CRITICAL09 Jun 2026
SQL injection in user.get API
70RISK
open
GitHub PoC
jenniferreire26/CVE-2024-21182
CVE-2024-21182HIGHunder attack09 Jun 2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
93RISK
open
GitHub PoC
jenniferreire26/CVE-2026-35616
CVE-2026-35616CRITICALunder attack09 Jun 2026
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta
100RISK
open
GitHub PoC
jenniferreire26/CVE-2026-41089
CVE-2026-41089CRITICAL09 Jun 2026
Windows Netlogon Remote Code Execution Vulnerability
70RISK
open
GitHub PoC
kennedy-aikohi/mcpjam-cve-2026-23744-validator
CVE-2026-23744CRITICAL09 Jun 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RISK
open
GitHub PoC
dotCMS Pre-auth SQL Injection
CVE-2026-8054CRITICAL09 Jun 2026
Unauthenticated SQL Injection in dotCMS Publish Audit API
63RISK
open
GitHub PoC
Go Proof of Concept (PoC) exploit for Flowise CustomMCP Remote Code Execution (RCE) CVE-2025-59528
CVE-2025-59528CRITICAL09 Jun 2026
Flowise has Remote Code Execution vulnerability
85RISK
open
GitHub PoC1
CVE-2026-48907: Unauthenticated RCE in JCE (Proof Of Concept)
CVE-2026-48907CRITICALunder attack09 Jun 2026
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RISK
open
GitHub PoC
jenniferreire26/CVE-2026-23479
CVE-2026-23479HIGH09 Jun 2026
redis-server use-after-free in unblock client flow may allow remote code execution
41RISK
open
GitHub PoC
CVE-2024-52011 - Draft
CVE-2024-52011HIGH09 Jun 2026
launch-editor vulnerable to command injection via the crafted request on Windows
41RISK
open
GitHub PoC
PoC and writeup for CVE-2026-46395: unauthenticated private key disclosure via broken HMAC in HAXcms Node.js (CWE-321/CWE-200). Authorized security research only.
CVE-2026-46395CRITICAL09 Jun 2026
HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation
48RISK
open
GitHub PoC
jenniferreire26/CVE-2026-28318
CVE-2026-28318HIGHunder attack09 Jun 2026
SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability
83RISK
open
GitHub PoC
jenniferreire26/CVE-2026-48595
CVE-2026-48595HIGH09 Jun 2026
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
21RISK
open
GitHub PoC
PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.
CVE-2026-46394HIGH09 Jun 2026
HAX CMS Vulnerable to Command Injection using Git.php
41RISK
open
GitHub PoC
Patched google_gax 0.4.1 for Tesla 1.18.3+ compatibility (CVE-2026-48598)
CVE-2026-48598LOW09 Jun 2026
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
28RISK
open
GitHub PoC
jenniferreire26/CVE-2026-33829
CVE-2026-33829MEDIUM09 Jun 2026
Windows Snipping Tool Spoofing Vulnerability
33RISK
open
GitHub PoC
jenniferreire26/CVE-2026-45659
CVE-2026-45659HIGHunder attackransomware09 Jun 2026
Microsoft SharePoint Remote Code Execution Vulnerability
93RISK
open
GitHub PoC
v3s9er/CVE-2026-52885
CVE-2026-52885HIGH09 Jun 2026
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
41RISK
open
GitHub PoC
CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated PHP Object Injection -> Remote Code Execution
CVE-2026-45247CRITICALunder attack09 Jun 2026
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
83RISK
open
GitHub PoC
CVE-2021-44228 漏洞复现完整记录(含环境搭建、触发验证)
CVE-2021-44228CRITICALunder attackransomware09 Jun 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.